Bug#787505: libnss3: NSS 3.19.1 breaks icedove IMAPS to server with DH 786 temp key

Ben Caradoc-Davies ben at transient.nz
Mon Jun 22 05:52:32 UTC 2015


On 21/06/15 11:33, Ben Caradoc-Davies wrote:
> The best solution is still for all servers to use strong keys (world
> peace, anyone?).

My IMAPS service provider just responded to my request and upgraded to a 
strong DH temp key. Perhaps world peace is still possible!  :-)

$ openssl s_client -connect ub007lcs04.cbr.the-server.net.au:993
[...]
Server Temp Key: DH, 2048 bits
[...]

This also means that I no longer have a weak temp key to test against.

Kind regards,

-- 
Ben Caradoc-Davies <ben at transient.nz>
Director
Transient Software Limited <http://transient.nz/>
New Zealand



More information about the pkg-mozilla-maintainers mailing list