<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mod_nss.git, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/'/>
<entry>
<title>Add Vitezslav Cizek and Christian Heimes to AUTHORS</title>
<updated>2016-03-01T16:47:38+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-03-01T16:47:38+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=35647512beb7b2436b4dc765941145aa8b2ced3c'/>
<id>35647512beb7b2436b4dc765941145aa8b2ced3c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Update ChangeLog: DHE ciphers, gencert, FIPS, permission, ciphers</title>
<updated>2016-03-01T16:42:27+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-29T22:41:39+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=a06c95d3b9bbefd6a4bf6c6561d6e32891f791f4'/>
<id>a06c95d3b9bbefd6a4bf6c6561d6e32891f791f4</id>
<content type='text'>
* Check for Apache user owner/group read permissions of NSS database
* Update default ciphers to something more modern and secure
* Fix test for DH cipher directive
* Check for test and netstat before trying to use them
* Don't ignore NSSProtocol when NSSFIPS is enabled
  Based on patch by Matthew Harmsen &lt;mharmsen@redhat.com&gt;
* Use proper shell syntax to avoid creating /0
* tests: Centralize the openssl ciphers flags when comparing
* Basic test case for DHE cipher negotiation
* Remove -DH from test strings, duplicate test, fix test
* Add server support for DHE ciphers.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* Check for Apache user owner/group read permissions of NSS database
* Update default ciphers to something more modern and secure
* Fix test for DH cipher directive
* Check for test and netstat before trying to use them
* Don't ignore NSSProtocol when NSSFIPS is enabled
  Based on patch by Matthew Harmsen &lt;mharmsen@redhat.com&gt;
* Use proper shell syntax to avoid creating /0
* tests: Centralize the openssl ciphers flags when comparing
* Basic test case for DHE cipher negotiation
* Remove -DH from test strings, duplicate test, fix test
* Add server support for DHE ciphers.
</pre>
</div>
</content>
</entry>
<entry>
<title>Update default cipher set to include stronger ciphers</title>
<updated>2016-03-01T16:42:27+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-03-01T16:33:25+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=baa0d0257d14725790bda2b727b722f8829ade23'/>
<id>baa0d0257d14725790bda2b727b722f8829ade23</id>
<content type='text'>
Insecure or less secure algorithms such as RC4, DES and 3DES are
removed. Perfect forward secrecy suites with ephemeral ECDH key
exchange have been added. IE 8 on Windows XP is no longer
supported.

https://fedorahosted.org/mod_nss/ticket/5
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Insecure or less secure algorithms such as RC4, DES and 3DES are
removed. Perfect forward secrecy suites with ephemeral ECDH key
exchange have been added. IE 8 on Windows XP is no longer
supported.

https://fedorahosted.org/mod_nss/ticket/5
</pre>
</div>
</content>
</entry>
<entry>
<title>Check filesystem permissions on NSS database at startup</title>
<updated>2016-03-01T16:42:27+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-03-01T03:33:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=105d65bfedfa0e381dcebd197ef67aab799fc8b1'/>
<id>105d65bfedfa0e381dcebd197ef67aab799fc8b1</id>
<content type='text'>
See if the configured user has read access to the NSS database
during initialization so the server can gracefully shutdown
rather than ending up in a forking loop because the database is
owned by root and is therefore unreadable once Apache starts
forking.

Adds a new configuration option, NSSSkipPermissionCheck &lt;on/off&gt;,
to skip this check in case something goes wrong.

https://fedorahosted.org/mod_nss/ticket/3
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
See if the configured user has read access to the NSS database
during initialization so the server can gracefully shutdown
rather than ending up in a forking loop because the database is
owned by root and is therefore unreadable once Apache starts
forking.

Adds a new configuration option, NSSSkipPermissionCheck &lt;on/off&gt;,
to skip this check in case something goes wrong.

https://fedorahosted.org/mod_nss/ticket/3
</pre>
</div>
</content>
</entry>
<entry>
<title>Change argumement order in make check so sqlite tests run</title>
<updated>2016-03-01T16:42:27+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-03-01T00:05:08+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=8e8befca612a8f70b9d47de5393c134aecf81494'/>
<id>8e8befca612a8f70b9d47de5393c134aecf81494</id>
<content type='text'>
Change 184804c82daf7fe04dfb0b0ecdc3e06be0c103c1 modified the
way arguments are handled in test/setup.sh such that sql: was
being dropped so tests were not being executed against sqlite
databases.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change 184804c82daf7fe04dfb0b0ecdc3e06be0c103c1 modified the
way arguments are handled in test/setup.sh such that sql: was
being dropped so tests were not being executed against sqlite
databases.
</pre>
</div>
</content>
</entry>
<entry>
<title>Check for test and netstat before trying to use them</title>
<updated>2016-02-29T21:45:09+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-29T21:43:14+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=ce5a624ca88bcccf1591265d26bc28d27e822da1'/>
<id>ce5a624ca88bcccf1591265d26bc28d27e822da1</id>
<content type='text'>
These may not be available on all systems. Work around it best
we can. In the case of netstat this can be replaced by using
/dev/urandom or /dev/random instead and piping it through tr
to produce only ASCII strings.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
These may not be available on all systems. Work around it best
we can. In the case of netstat this can be replaced by using
/dev/urandom or /dev/random instead and piping it through tr
to produce only ASCII strings.
</pre>
</div>
</content>
</entry>
<entry>
<title>Don't ignore NSSProtocol when NSSFIPS is enabled</title>
<updated>2016-02-29T21:44:53+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-29T18:56:20+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=ef90eb1b1e5b68aa53164813bd4a70697dcbef17'/>
<id>ef90eb1b1e5b68aa53164813bd4a70697dcbef17</id>
<content type='text'>
The value was always being set to TLS 1.0, 1.1 and 1.2, ignoring
the configuration value.

I suspect this is because this code dated to when only SSL2, 3 and
TLS 1.0 were supported so it only enabled TLS v1.0. When 1.1 and
1.2 were added it seemed natural to automatically enable those
as well. Natural but incorrect.

Based on patch by Matthew Harmsen &lt;mharmsen@redhat.com&gt;

RHBZ #1312052
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The value was always being set to TLS 1.0, 1.1 and 1.2, ignoring
the configuration value.

I suspect this is because this code dated to when only SSL2, 3 and
TLS 1.0 were supported so it only enabled TLS v1.0. When 1.1 and
1.2 were added it seemed natural to automatically enable those
as well. Natural but incorrect.

Based on patch by Matthew Harmsen &lt;mharmsen@redhat.com&gt;

RHBZ #1312052
</pre>
</div>
</content>
</entry>
<entry>
<title>Use proper shell syntax to avoid creating /0</title>
<updated>2016-02-29T21:09:17+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-24T14:18:25+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=31a5ff02f6ff251629d597d43ee88fadb135ff8b'/>
<id>31a5ff02f6ff251629d597d43ee88fadb135ff8b</id>
<content type='text'>
I used if [ $x &gt; 0 ]; ... which is obviously wrong :-(

https://bugzilla.redhat.com/show_bug.cgi?id=1311392
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
I used if [ $x &gt; 0 ]; ... which is obviously wrong :-(

https://bugzilla.redhat.com/show_bug.cgi?id=1311392
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix test for DH cipher directive</title>
<updated>2016-02-29T21:09:17+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-29T19:45:44+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=ae8c616ade2199ca26bd39374707d44a04be7db3'/>
<id>ae8c616ade2199ca26bd39374707d44a04be7db3</id>
<content type='text'>
Since we don't support ADH ciphers can just ignore DH-*

Note that OpenSSL defines the DH- ciphers but does not implement
them so the DH string support is there only for compatibility.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Since we don't support ADH ciphers can just ignore DH-*

Note that OpenSSL defines the DH- ciphers but does not implement
them so the DH string support is there only for compatibility.
</pre>
</div>
</content>
</entry>
<entry>
<title>tests: Centralize the openssl ciphers flags when comparing</title>
<updated>2016-02-29T21:09:17+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-02-15T19:10:58+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=5b93aa509881c307050de41e88000c33e13080be'/>
<id>5b93aa509881c307050de41e88000c33e13080be</id>
<content type='text'>
I used to have a separate set of options when comparing the
NSS and OpenSSL ciphers. These differed between tests, sometimes
being just a difference in order. This just made the tests
hard to understand.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
I used to have a separate set of options when comparing the
NSS and OpenSSL ciphers. These differed between tests, sometimes
being just a difference in order. This just made the tests
hard to understand.
</pre>
</div>
</content>
</entry>
</feed>
