New functionality: * Bug 1252891 - Implemented EKU handling for IPsec IKE. * Bug 1423043 - Enable half-closed states for TLS. * Bug 1493215 - Enabled the following ciphersuites by default: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 TLS_RSA_WITH_AES_256_GCM_SHA384 Notable changes: * The following CA certificates were added: CN = Certigna Root CA CN = GTS Root R1 CN = GTS Root R2 CN = GTS Root R3 CN = GTS Root R4 CN = UCA Global G2 Root CN = UCA Extended Validation Root * The following CA certificates were removed: CN = AC Raíz Certicámara S.A. CN = Certplus Root CA G1 CN = Certplus Root CA G2 CN = OpenTrust Root CA G1 CN = OpenTrust Root CA G2 CN = OpenTrust Root CA G3 Bugs fixed in NSS 3.41: * Bug 1412829, Reject empty supported_signature_algorithms in Certificate Request in TLS 1.2 * Bug 1485864 - Cache side-channel variant of the Bleichenbacher attack (CVE-2018-12404) * Bug 1481271 - Resend the same ticket in ClientHello after HelloRetryRequest * Bug 1493769 - Set session_id for external resumption tokens * Bug 1507179 - Reject CCS after handshake is complete in TLS 1.3 |
||
---|---|---|
.. | ||
files | ||
patches | ||
buildlink3.mk | ||
DESCR | ||
distinfo | ||
Makefile | ||
PLIST |