[dev-tech-crypto] Release of NSS 3.94 on hold

2023-09-26 Thread Benjamin Beurdouche
Hi folks, We are currently holding on releasing NSS 3.94 for technical reasons. We expect to ship it by the end of the week... As usual you’ll get the release notes on the list as soon as it is ready. Sorry for the inconvenience, Best, Benjamin -- You received this message because you are subs

Re: [dev-tech-crypto] NSS 3.94 Release

2023-10-03 Thread Benjamin Beurdouche
Thank you a lot Anna for taking over this release ! Ben > On 3 Oct 2023, at 09:38, Anna Weine wrote: > > Dear all, > > Network Security Services (NSS) 3.94 was released on 2 October 2023. > > The HG tag is NSS_3_94_RTM. This version of NSS requires NSPR 4.35 or newer. > > NSS 3.94 source dis

Re: [dev-tech-crypto] NSS 3.95 Release

2023-11-27 Thread Benjamin Beurdouche
Thanks Anna for uploading the archive and sending out the email ! Thanks Dennis for handling that release ! B. > On 27 Nov 2023, at 11:06, Anna Weine wrote: > > Dear all, > > Network Security Services (NSS) 3.95 was released on 27 November 2023. > > The HG tag is NSS_3_95_RTM. This version of

[dev-tech-crypto] NSS 3.96.1 Release

2023-12-18 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.96.1 was tagged on 18th December 2023 and released today. The HG tag is NSS_3_96_1_RTM. This version of NSS requires NSPR 4.35 or newer. NSS 3.96.1 source distributions are available on ftp.mozilla.org for secure HTTPS downl

[dev-tech-crypto] Releasing NSS 3.96.1 instead of NSS 3.96.0

2023-12-18 Thread Benjamin Beurdouche
Dear all, Unfortunately due to issues with the release process we have inconsistent source code between the 3.96.0 tag in the NSS repo and the code that is on the FTP. The code for 3.96.0 available on the FTP contains some changes planned for the next release (namely DTLS 1.3). As we cannot c

[dev-tech-crypto] NSS 3.97 Release

2024-01-22 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.97 was tagged on January 22, 2024 and released today. The HG tag is NSS_3_97_RTM. This version of NSS requires NSPR 4.35 or newer. NSS 3.97 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/s

WELCOME to dev-tech-crypto

2021-04-02 Thread Benjamin Beurdouche
Dear All, Welcome to the new dev-tech-crypto mailing list in Mozilla's Google Workspace. The predecessor of this group, mozilla.dev.tech.crypto, had been running on ancient custom-patched mailman software since the early Mozilla days, which had limitations and sometimes loss of data. Therefore,

[dev-tech-crypto] NSS 3.64 Release

2021-04-15 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.64 was released on April 15th, 2021. The HG tag is NSS_3_64_RTM. NSS 3.64 requires NSPR 4.30 or newer. NSS 3.64 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/moz

[dev-tech-crypto] NSS 3.65 Release

2021-05-14 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.65 was released on May 13th, 2021. The HG tag is NSS_3_65_RTM. NSS 3.65 requires NSPR 4.30 or newer. NSS 3.65 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/mozil

[dev-tech-crypto] NSS 3.66 Release

2021-06-04 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.66 was released on May 27th, 2021. The HG tag is NSS_3_66_RTM. NSS 3.66 requires NSPR 4.30 or newer. NSS 3.66 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/mozil

[dev-tech-crypto] NSS 3.67 Release

2021-06-17 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.67 was released on June 10th, 2021. The HG tag is NSS_3_67_RTM. NSS 3.67 requires NSPR 4.30 or newer. NSS 3.67 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/mozilla.org/security/nss/relea

Re: [dev-tech-crypto] NSS 3.69 Release

2021-08-20 Thread Benjamin Beurdouche
Hi all, Interesting, I had no knowledge of those specific needs for RedHat. I’ll document that in the release management page so that it doesn’t happen in the future. Bob, would it be useful if I released a 3.68.1 version reverting the NSPR requirements to 4.30 early next week ? Kai, if the s

[dev-tech-crypto] NSS 3.68 Release (ESR)

2021-08-31 Thread Benjamin Beurdouche
Dear all, Please find below the missing release notes of 3.68 ESR for posterity. Network Security Services (NSS) 3.68 ESR was released on 8 July 2021. The HG tag is NSS_3_68_RTM. NSS 3.68 requires NSPR 4.32 or newer. NSS 3.68 source distributions are available on ftp.mozilla.org

[dev-tech-crypto] NSS 3.69.1 Release

2021-08-31 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.69.1 was released on 26 August 2021. The HG tag is NSS_3_69_1_RTM. NSS 3.69.1 requires NSPR 4.32 or newer. NSS 3.69.1 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] NSS documentation moving to firefox-source-docs.mozilla.org

2021-08-31 Thread Benjamin Beurdouche
Dear all, As MDN has started removing documentation from many external projects, NSS has to move its documentation. We started bringing the documentation back into the NSS tree in the sphinx format which will be rendered at https://firefox-source-docs.mozilla.org/security/nss/index.html

[dev-tech-crypto] NSS 3.70 Release

2021-09-04 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.70 was released on 4 September 2021. The HG tag is NSS_3_70_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.70 source distributions are available on ftp.mozilla.org for secure HTTPS download:

Re: [dev-tech-crypto] NSS 3.70 Release

2021-09-05 Thread Benjamin Beurdouche
It should work now... B. > On 5 Sep 2021, at 06:45, Đoàn Trần Công Danh wrote: > > Hello teams, > > On 2021-09-04 20:36:06+0200, Benjamin Beurdouche > wrote: >> Network Security Services (NSS) 3.70 was released on 4 September 2021. >> >> The HG tag

[dev-tech-crypto] Expiration of IdenTrust "DST Root CA X3"

2021-09-29 Thread Benjamin Beurdouche
Dear all, This email is to let you know about the expiration of IdenTrust “DST Root CA X3”. This root is part of the trust chain for let’s encrypt intermediates and will expire on Sep 30 14:01:15 2021 GMT. We noticed this quite recently so I expect some of you might also have missed it. The

[dev-tech-crypto] NSS 3.71 Release

2021-09-30 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.71 was released on 30 September 2021. The HG tag is NSS_3_71_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.71 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] NSS 3.72 Release

2021-10-28 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.72 was released on 28 October 2021. The HG tag is NSS_3_72_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.72 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] CVE-2021-43527: Heap overflow in NSS when verifying DSA/RSA-PSS DER-encoded signatures

2021-12-01 Thread Benjamin Beurdouche
Dear all, We just released NSS 3.73 and NSS 3.68.1(ESR). Those versions contain the fix for CVE-2021-43527 which affected previous versions. The release notes for those versions of NSS will follow on this list shortly. Best, Benjamin https://www.mozilla.org/en-US/security/advisories/mfsa2021-

[dev-tech-crypto] NSS 3.73 Release (Important)

2021-12-01 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.73 was released on 01 December 2021. This release contains an important security fix for CVE-2021-43527: https://www.mozilla.org/en-US/security/advisories/mfsa2021-51/ The HG tag is NS

[dev-tech-crypto] NSS 3.68.1 (ESR) Release (Important)

2021-12-01 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.68.1 (ESR) was released on 01 December 2021. This release contains an important security fix for CVE-2021-43527: https://www.mozilla.org/en-US/security/advisories/mfsa2021-51/ The HG t

[dev-tech-crypto] NSS 3.72.1 Release

2021-12-16 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.72.1 was released on 15 December 2021. The HG tag is NSS_3_72_1_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.72.1 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] NSS 3.73.1 Release

2021-12-16 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.73.1 was released on 15 December 2021. The HG tag is NSS_3_73_1_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.73.1 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] NSS 3.68.2 (ESR) Release

2021-12-16 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.68.2 was released on 15 December 2021. The HG tag is NSS_3_68_2_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.68.2 source distributions are available on ftp.mozilla.org for secure HTTPS download:

[dev-tech-crypto] Out of cycle releases for NSS 3.68.2, 3.72.1 and 3.73.1

2021-12-16 Thread Benjamin Beurdouche
Dear all, Yesterday, we made thee out of cycle releases for NSS to include the following changes - Bug 966856 - Add SHA-2 support to mozilla::pkix's OCSP implementation We did this to rapidly fix a webcompat issue between Firefox and Microsoft websites. https://bugzilla.mozilla.org/show_bug.cg

Re: [dev-tech-crypto] NSS and MSVS 2022

2022-01-04 Thread Benjamin Beurdouche
Hi Burak, Thanks for looking into this! If I am correct there is a gyp fork maintained by Node.js and called gyp-next. We have been contemplating moving NSS to use gyp-next but haven’t got to try yet. Any chance you could have a look and see if building NSS with gyp-next using MSVC 17 would work

[dev-tech-crypto] NSS 3.74 Release

2022-01-06 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.74 was released on 06 January 2022. The HG tag is NSS_3_74_RTM. This version of NSS requires NSPR 4.32 or newer. NSS 3.74 source distributions are available on ftp.mozilla.org for secure HTTPS download:

Re: [dev-tech-crypto] gyp VS. gyp-next VS. gn for building NSS/NSPR

2022-04-06 Thread Benjamin Beurdouche
Hi, > On 6 Apr 2022, at 08:17, Miklos Vajna wrote: > > Hi, > > On Tue, Apr 05, 2022 at 10:41:07AM -0700, George Lee > wrote: >> Is it currently preferred to use gyp, gyp-next, or gn to build NSS/NSPR? Or >> maybe it doesn't matter much? It doesn’t matter much at the moment. I haven’t tested

Re: [dev-tech-crypto] Re: Build NSS 3.68.1 on Solaris 11 x86 with Solarisstudio 12.5

2022-06-27 Thread Benjamin Beurdouche
Hi Rahul, We don’t have Solaris in our CI (because it is not a tier1 platform) so we can’t see these kind of issues… thanks for reaching out. It looks like the makefile is attempting to build a vectorized version of chachapoly on an intel platform supporting AVX2 but that for some reason the f

[dev-tech-crypto] NSS 3.79.3 ESR Release

2023-01-10 Thread Benjamin Beurdouche
Dear all, Network Security Services (NSS) 3.79.3 was released out of cycle on 10 January 2022. The HG tag is NSS_3_79_3_RTM. This version of NSS requires NSPR 4.31.2 or newer. This is a backport of the TrustCor Root CA changes to NSS ESR (already available since NSS 3.86) which will be used in

[dev-tech-crypto] NSS 3.105 Release

2024-09-26 Thread 'Benjamin Beurdouche' via dev-tech-crypto@mozilla.org
Dear all, Network Security Services (NSS) 3.105 was tagged on 26th September 2024 and released today. The HG tag is NSS_3_105_RTM. This version of NSS requires NSPR 4.35 or newer. NSS 3.105 source distributions are available on ftp.mozilla.org for secure HTTPS downloa