[El-errata] ELEA-2022-6596 Oracle Linux 9 nss bug fix and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Sep 22 12:25:29 UTC 2022


Oracle Linux Enhancement Advisory ELEA-2022-6596

http://linux.oracle.com/errata/ELEA-2022-6596.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
nspr-4.34.0-14.el9_0.i686.rpm
nspr-4.34.0-14.el9_0.x86_64.rpm
nspr-devel-4.34.0-14.el9_0.i686.rpm
nspr-devel-4.34.0-14.el9_0.x86_64.rpm
nss-3.79.0-14.el9_0.i686.rpm
nss-3.79.0-14.el9_0.x86_64.rpm
nss-devel-3.79.0-14.el9_0.i686.rpm
nss-devel-3.79.0-14.el9_0.x86_64.rpm
nss-softokn-3.79.0-14.el9_0.i686.rpm
nss-softokn-3.79.0-14.el9_0.x86_64.rpm
nss-softokn-devel-3.79.0-14.el9_0.i686.rpm
nss-softokn-devel-3.79.0-14.el9_0.x86_64.rpm
nss-softokn-freebl-3.79.0-14.el9_0.i686.rpm
nss-softokn-freebl-3.79.0-14.el9_0.x86_64.rpm
nss-softokn-freebl-devel-3.79.0-14.el9_0.i686.rpm
nss-softokn-freebl-devel-3.79.0-14.el9_0.x86_64.rpm
nss-sysinit-3.79.0-14.el9_0.x86_64.rpm
nss-tools-3.79.0-14.el9_0.x86_64.rpm
nss-util-3.79.0-14.el9_0.i686.rpm
nss-util-3.79.0-14.el9_0.x86_64.rpm
nss-util-devel-3.79.0-14.el9_0.i686.rpm
nss-util-devel-3.79.0-14.el9_0.x86_64.rpm

aarch64:
nspr-4.34.0-14.el9_0.aarch64.rpm
nspr-devel-4.34.0-14.el9_0.aarch64.rpm
nss-3.79.0-14.el9_0.aarch64.rpm
nss-devel-3.79.0-14.el9_0.aarch64.rpm
nss-softokn-3.79.0-14.el9_0.aarch64.rpm
nss-softokn-devel-3.79.0-14.el9_0.aarch64.rpm
nss-softokn-freebl-3.79.0-14.el9_0.aarch64.rpm
nss-softokn-freebl-devel-3.79.0-14.el9_0.aarch64.rpm
nss-sysinit-3.79.0-14.el9_0.aarch64.rpm
nss-tools-3.79.0-14.el9_0.aarch64.rpm
nss-util-3.79.0-14.el9_0.aarch64.rpm
nss-util-devel-3.79.0-14.el9_0.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/nss-3.79.0-14.el9_0.src.rpm



Description of changes:

[3.79.0-14]
- Update fips_algorithms.h to match the final FIPS requirements
- Disable delegated credentials

[3.79.0-13]
- remove OAEP from the FIPS indicators

[3.79.0-12]
- only turn off rand changes on all non-fips kernels

[3.79.0-11]
- only turn off rand changes on ppc64le at build-test time.

[3.79.0-10]
- turn off rand changes on ppc64le

[3.79.0-9]
- FIPS 140-3 changes

[3.79.0-8]
- fix encoding issue with NULL passwords

[3.79.0-7]
- more complete fix for cert auth regression crash

[3.79.0-6]
- Remove debugging printf from a patch
- increase the pbe cache size to handle reusing the same token key.

[3.79.0-5]
- FIPS 140-3 changes
-  Reject Small RSA keys, 1024 bit keys are marked as FIP OK when verifying, reject
   signature keys by policy
-  Allow applications to retrigger selftests on demand.

[3.79.0-4]
- server passive fix

[3.79.0-3]
- fix regressions in test suite

[3.79.0-2]
- fix nspr coverify issues.

[3.79.0-1]
- update to NSS 3.79
- update to NSPR 4.34
- change FIPS Modulename to conform with our final module standard




More information about the El-errata mailing list