e4b4d0480e59e012ab5a13ac29c86a0a05f1c948: Error strings for new error codes.
relyea%netscape.com - Wed, 17 Aug 2011 05:01:44 +0000 - rev 10076
Error strings for new error codes.
3cf9d2e7b4d93c15c77ba5978f0ac9776026e435: Bug 236613: change to MPL/LGPL/GPL tri-license.
gerv%gerv.net - Wed, 17 Aug 2011 05:01:43 +0000 - rev 10075
Bug 236613: change to MPL/LGPL/GPL tri-license.
808e93ff62c4c4d187009871769e6a551e95a9e2: Fix for bug 233605 . Check CRL entry extensions after partial decoding. Also add some new CRL decoding errors. r=nelsonb
jpierre%netscape.com - Wed, 17 Aug 2011 05:01:42 +0000 - rev 10074
Fix for bug 233605 . Check CRL entry extensions after partial decoding. Also add some new CRL decoding errors. r=nelsonb
cc6c7191531746118ef5de13231a714fdfa83dde: Fix for bug 94413 - OCSP needs more fine tuned error messages. r=wtc
jpierre%netscape.com - Wed, 17 Aug 2011 05:01:41 +0000 - rev 10073
Fix for bug 94413 - OCSP needs more fine tuned error messages. r=wtc
e0495b6ce02ffc4ba2193c9f8ca2b2b099940ab1: Add support for Elliptic Curve Cryptography. Bug 195135.
nelsonb%netscape.com - Wed, 17 Aug 2011 05:01:40 +0000 - rev 10072
Add support for Elliptic Curve Cryptography. Bug 195135. Modified Files: cmd/lib/SECerrs.h cmd/selfserv/selfserv.c cmd/tstclnt/tstclnt.c lib/cryptohi/keyhi.h lib/cryptohi/keythi.h lib/cryptohi/seckey.c lib/cryptohi/secvfy.c lib/freebl/Makefile lib/freebl/blapi.h lib/freebl/blapit.h lib/freebl/ldvector.c lib/freebl/loader.c lib/freebl/loader.h lib/freebl/manifest.mn lib/nss/nss.def lib/pk11wrap/pk11skey.c lib/pk11wrap/pk11slot.c lib/softoken/lowkeyti.h lib/softoken/manifest.mn lib/softoken/pkcs11.c lib/softoken/pkcs11c.c lib/softoken/pkcs11t.h lib/ssl/ssl3con.c lib/ssl/ssl3prot.h lib/ssl/sslcon.c lib/ssl/sslenum.c lib/ssl/sslimpl.h lib/ssl/sslinfo.c lib/ssl/sslproto.h lib/ssl/sslsecur.c lib/ssl/sslsock.c lib/ssl/sslt.h lib/util/secerr.h lib/util/secoid.c lib/util/secoidt.h Added Files: lib/freebl/GFp_ecl.c lib/freebl/GFp_ecl.h lib/freebl/ec.c lib/freebl/ec.h lib/softoken/ecdecode.c
82c6f1852054655e2c1f16cf4ea0de29fcfec776: bug 172247, don't allow import of duplicate issuer/serial certs
ian.mcgreer%sun.com - Wed, 17 Aug 2011 05:01:39 +0000 - rev 10071
bug 172247, don't allow import of duplicate issuer/serial certs
58be288c61e48841d97212a7a7de7ae2a26caa14: Make grammar, punctuation, capitalization, and content changes suggested by
relyea%netscape.com - Wed, 17 Aug 2011 05:01:38 +0000 - rev 10070
Make grammar, punctuation, capitalization, and content changes suggested by nelson.
7a9135a62699b62a884d11c070034f6537168553: Add missing errors from secerr.h in lib/util
relyea%netscape.com - Wed, 17 Aug 2011 05:01:37 +0000 - rev 10069
Add missing errors from secerr.h in lib/util
d1625cff2fb38b519d700b7c917f9b80e94904d4: Fix a crash. An attempt to move a sensitive key longer than 48 bytes
nelsonb%netscape.com - Wed, 17 Aug 2011 05:01:36 +0000 - rev 10068
Fix a crash. An attempt to move a sensitive key longer than 48 bytes from one token to another will no longer crash. Instead, it will fail with the new error code SEC_ERROR_CANNOT_MOVE_SENSITIVE_KEY. Bug 97887. In addition, DHE key pairs are now generated with CKA_SENSITIVE false.
e1a75eb88489ee0d60f499f2e982d6ec74143cde: Initial NSS Open Source checkin
relyea%netscape.com - Wed, 17 Aug 2011 05:01:35 +0000 - rev 10067
Initial NSS Open Source checkin
343fcb6b22c3c7a58af39c7c46bf109d871e606e: bustage fix
kaie%kuix.de - Wed, 10 Aug 2011 15:14:24 +0000 - rev 10066
bustage fix
a22b181b9a56ac20180c5efd87d07b268a1f8c77: Bug 676886, NSS' internal HTTP client should exclude :port for OCSP requests on default port 80, r=wtc
kaie%kuix.de - Wed, 10 Aug 2011 12:31:54 +0000 - rev 10065
Bug 676886, NSS' internal HTTP client should exclude :port for OCSP requests on default port 80, r=wtc
6d2059f5f67e9c633e2c7a88adfdd7393093a0d7: Set version number to 3.12.12 beta NSS_3_12_BRANCH
kaie%kuix.de - Tue, 09 Aug 2011 18:16:19 +0000 - rev 10064
Set version number to 3.12.12 beta
4678258e3dde02c6f5297ac14aa6622e1c9f343a: Update version numbers to NSS 3.12.11 final release NSS_3_12_BRANCH NSS_3_12_11_RTM
kaie%kuix.de - Tue, 09 Aug 2011 15:56:31 +0000 - rev 10063
Update version numbers to NSS 3.12.11 final release
1ae61eee09957f676ed446dcc380a9d75d9563ec: Bug 668397: remove support for Fortezza certificates and keys from NSS_3_12_BRANCH NSS_3_12_11_BETA3
wtc%google.com - Fri, 05 Aug 2011 12:27:52 +0000 - rev 10062
Bug 668397: remove support for Fortezza certificates and keys from cert_VerifyCertChainOld and seckey_ExtractPublicKey. The bug was reported by Tavis Ormandy <taviso@sdf.lonestar.org>. The patch was written by Brian Smith <bsmith@mozilla.com>. r=rrelyea,wtc. Modified Files: Tag: NSS_3_12_BRANCH certhigh/certvfy.c cryptohi/seckey.c
50d2e1f0b9ea98a6eddc116c165747725eac68bb: Bug 662557: Set pkixErrorClass and pkixErrorCode if localRevChecker orexternalRevChecker fails, otherwise we would end up reporting the default NSS_3_12_BRANCH
wtc%google.com - Fri, 05 Aug 2011 02:55:24 +0000 - rev 10061
Bug 662557: Set pkixErrorClass and pkixErrorCode if localRevChecker orexternalRevChecker fails, otherwise we would end up reporting the default error code PKIX_ALLOCERROR (value 0). Add the PKIX_CHECK_NO_GOTO macro. The patch is written by Kai Engert <kaie@kuix.de>. r=wtc. Modified Files: Tag: NSS_3_12_BRANCH pkix/checker/pkix_revocationchecker.c pkix/util/pkix_tools.h
66bca88b1b24b88f5b14e27a5c6f5677947c49d0: Bug 662557: Set pkixErrorClass and pkixErrorCode if localRevChecker or
wtc%google.com - Fri, 05 Aug 2011 02:53:24 +0000 - rev 10060
Bug 662557: Set pkixErrorClass and pkixErrorCode if localRevChecker or externalRevChecker fails, otherwise we would end up reporting the default error code PKIX_ALLOCERROR (value 0). Add the PKIX_CHECK_NO_GOTO macro. The patch is written by Kai Engert <kaie@kuix.de>. r=wtc. Modified Files: pkix/checker/pkix_revocationchecker.c pkix/util/pkix_tools.h
779cc6149a6c93cfc795e65fed947e1812cfb689: Bug 673413: disallow !item->data && item->len in MatchComponentType.
wtc%google.com - Fri, 05 Aug 2011 02:06:58 +0000 - rev 10059
Bug 673413: disallow !item->data && item->len in MatchComponentType. r=rrelyea.
38323e0a5b395fc82881a9b276612e8459a249e0: Bug 217721: change the certUsageObjectSigner case back to NSS_3_12_BRANCH
wtc%google.com - Fri, 05 Aug 2011 01:16:27 +0000 - rev 10058
Bug 217721: change the certUsageObjectSigner case back to KU_DIGITAL_SIGNATURE because RFC 5280 says code signing needs digitalSignature, as opposed to "digitalSignature and/or nonRepudiation". r=rrelyea. Modified Files: Tag: NSS_3_12_BRANCH certdb.c
d3ab6c75e17cc4b2836d36975aae4da48c2ed239: Bug 217721: change the certUsageObjectSigner case back to
wtc%google.com - Fri, 05 Aug 2011 01:13:14 +0000 - rev 10057
Bug 217721: change the certUsageObjectSigner case back to KU_DIGITAL_SIGNATURE because RFC 5280 says code signing needs digitalSignature, as opposed to "digitalSignature and/or nonRepudiation". R=rrelyea.
(0) -10000 -3000 -1000 -300 -100 -50 -20 +20 +50 +100 +300 +1000 +3000 tip