[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-07-05 Thread Bug Watch Updater
** Changed in: nss Status: Unknown => Fix Released ** Changed in: nss Importance: Unknown => Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1465014 Title: after update

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-07-05 Thread Haw Loeung
** Bug watch added: Mozilla Bugzilla #1138554 https://bugzilla.mozilla.org/show_bug.cgi?id=1138554 ** Also affects: nss via https://bugzilla.mozilla.org/show_bug.cgi?id=1138554 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of U

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-27 Thread Alberto Salvia Novella
** Changed in: firefox (Ubuntu) Status: Confirmed => Triaged ** Changed in: firefox (Ubuntu) Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/146

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-25 Thread Marc Deslauriers
** Also affects: firefox (Ubuntu) Importance: Undecided Status: New ** Changed in: firefox (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bug

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-25 Thread Alberto Salvia Novella
** Changed in: nss (Ubuntu) Status: Confirmed => Triaged ** Changed in: firefox (Ubuntu) Status: Confirmed => Triaged ** No longer affects: firefox (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu.

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-21 Thread Haw Loeung
3.19.2 was just released[1] with: """ Notable Changes in NSS 3.19.2 Bug 1172128 - In NSS 3.19.1, the minimum key sizes that the freebl cryptographic implementation (part of the softoken cryptographic module used by default by NSS) was willing to generate or use was increased - for RSA keys, to

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-18 Thread Alberto Salvia Novella
** Changed in: firefox (Ubuntu) Importance: Undecided => Critical ** Changed in: nss (Ubuntu) Importance: Undecided => Critical ** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscri

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-16 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: nss (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1465014 T

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-16 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: firefox (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/146501

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-15 Thread Haw Loeung
https://hg.mozilla.org/projects/nss/rev/ae72d76f8d24 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1465014 Title: after update still vulnerable against LOGJAM To manage notifications

[Bug 1465014] Re: after update still vulnerable against LOGJAM

2015-06-15 Thread Haw Loeung
Chrome and Firefox both uses NSS. NSS 3.19.1 contains fixes to mitigate logjam by increasing the minimum modulus size for Diffie-Hellman keys to 1023 bits[1]. Maybe we can look into backporting that. [1]https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.19.1_release_notes ** Al