Bug#588806: libnss3-1d: Impossible to enable FIPS mode

Mike Hommey mh at glandium.org
Mon Jul 12 13:07:54 UTC 2010


found 588806 3.12.4-1
thanks

On Mon, Jul 12, 2010 at 02:40:32PM +0200, Mike Hommey wrote:
> On Mon, Jul 12, 2010 at 03:31:11PM +0300, Lior Okman wrote:
> > 
> > Package: libnss3-1d
> > Version: 3.12.6-2
> > Severity: normal
> > 
> > 
> > It is impossible to enable FIPS mode using the libnss3-1d binaries available
> > in Squeeze.
> > 
> > The same functionality works both in the Lenny version and in upstream.
> > 
> > squeeze:~# mkdir db
> > squeeze:~# cd db
> > squeeze:~/db# modutil  -create -dbdir .
> > squeeze:~/db# modutil -fips true -dbdir .
> > 
> > security library: invalid arguments.
> > ERROR: Unable to switch FIPS modes.
> > 
> > This is caused by invalid .chk files packaged with the shared objects.
> 
> More subtil: there is no chk for libnssdbm3.so, which appeared quite
> recently.

Actually, it appeared earlier than I thought, and is shipped in Lenny
already. BUT, it has only been part of what is checked for FIPS mode
since 3.12.4-1.

Mike





More information about the pkg-mozilla-maintainers mailing list