Sept. 15, 2022 Alexey Gladkov 3.83-alt1 |
- New version (3.83).
- Certificate Authority Changes:
+ Add CN=DIGITALSIGN GLOBAL ROOT ECDSA CA
+ Add CN=DIGITALSIGN GLOBAL ROOT RSA CA
+ Add CN=Security Communication ECC RootCA1
+ Add CN=Security Communication RootCA3
+ Remove CN=Global Chambersign Root |
Sept. 6, 2022 Alexey Gladkov 3.82-alt1 |
- New version (3.82). |
July 22, 2022 Alexey Gladkov 3.81-alt1 |
- New version (3.81).
- Certificate Authority Changes:
+ Add CN=Certainly Root E1
+ Add CN=Certainly Root R1
+ Add CN=DigiCert SMIME ECC P384 Root G5
+ Add CN=DigiCert SMIME RSA4096 Root G5
+ Add CN=DigiCert TLS ECC P384 Root G5
+ Add CN=DigiCert TLS RSA4096 Root G5
+ Add CN=E-Tugra Global Root CA ECC v3
+ Add CN=E-Tugra Global Root CA RSA v3
+ Remove CN=Hellenic Academic and Research Institutions RootCA 2011 |
June 8, 2022 Alexey Gladkov 3.79-alt1 |
- New version (3.79). |
April 28, 2022 Alexey Gladkov 3.78-alt1 |
- New version (3.78). |
April 1, 2022 Alexey Gladkov 3.77-alt1 |
- New version (3.77).
- Certificate Authority Changes:
+ Add CN=Telia Root CA v2
+ Add CN=D-TRUST BR Root CA 1 2020
+ Add CN=D-TRUST EV Root CA 1 2020
+ Remove CN=DigiNotar PKIoverheid CA Organisatie - G2
+ Remove CN=Trustwave Organization Issuing CA, Level 2
+ Remove TURKTRUST Mis-issued Intermediate CA 1
+ Remove TURKTRUST Mis-issued Intermediate CA 2 |
March 8, 2022 Alexey Gladkov 3.76-alt1 |
- New version (3.76). |
Feb. 9, 2022 Alexey Gladkov 3.75-alt1 |
- New version (3.75). |
Jan. 7, 2022 Alexey Gladkov 3.74-alt1 |
- New version (3.74).
- Certificate Authority Changes:
+ Add HiPKI Root CA - G1
+ Add ISRG Root X2
+ Add vTrus Root CA
+ Add vTrus ECC Root CA
+ Add Autoridad de Certificacion Firmaprofesional CIF A62634068
+ Remove DST Root CA X3
+ Remove GlobalSign Root CA - R2
+ Remove Cybertrust Global Root
+ Replace GlobalSign ECC Root CA - R4
+ Replace GTS Root R1
+ Replace GTS Root R2
+ Replace GTS Root R3
+ Replace GTS Root R4 |
Dec. 1, 2021 Alexey Gladkov 3.73-alt1 |
- New version (3.73).
- Security fixes:
+ CVE-2021-43527: Heap overflow in NSS when verifying DSA/RSA-PSS DER-encoded signatures |
Nov. 11, 2021 Alexey Gladkov 3.72-alt2 |
- nss-utils: Install utilities used by fedora and opensuse (ALT#41317). |
Nov. 2, 2021 Alexey Gladkov 3.72-alt1 |
- New version (3.72). |
Oct. 6, 2021 Alexey Gladkov 3.71-alt1 |
- New version (3.71).
- Certificate Authority Changes:
+ Add CN=HARICA TLS RSA Root CA 2021
+ Add CN=HARICA TLS ECC Root CA 2021
+ Add CN=HARICA Client RSA Root CA 2021
+ Add CN=HARICA Client ECC Root CA 2021
+ Add CN=TunTrust Root CA |
Sept. 7, 2021 Alexey Gladkov 3.69.1-alt1 |
- New version (3.69.1). |
Aug. 10, 2021 Alexey Gladkov 3.69.0-alt1 |
- New version (3.69). |
July 17, 2021 Gleb Fotengauer-Malinovskiy 3.66.0-alt2 |
- Backported upstream fixes for POWER AES-GCM Vector Acceleration (ALT#40510)
(MBZ#1566124).
- Enabled testsuite. |
June 3, 2021 Alexey Gladkov 3.66.0-alt1 |
- New version (3.66).
- Certificate Authority Changes:
+ Add CN=GLOBALTRUST 2020
+ Add CN=ANF Secure Server Root CA
+ Add CN=Certum EC-384 CA
+ Add CN=Certum Trusted Root CA
+ Remove OU=Trustis FPS Root CA
+ Remove CN=QuoVadis Root Certification Authority
+ Remove CN=Sonera Class2 CA |
March 24, 2021 Alexey Gladkov 3.63.0-alt1 |
- New version (3.63).
- Certificate Authority Changes:
+ Add CN=GlobalSign Secure Mail Root R45
+ Add CN=GlobalSign Secure Mail Root E45
+ Add CN=GlobalSign Root R46
+ Add CN=GlobalSign Root E46
+ Add CN=AC RAIZ FNMT-RCM SERVIDORES SEGUROS
+ Remove CN=GeoTrust Primary Certification Authority - G2
+ Remove CN=VeriSign Universal Root Certification Authority
+ Turn off Websites trust bit for "Staat der Nederlanden Root CA - G3"
+ Turn off Websites trust bit for "Chambers of Commerce Root - 2008"
+ Turn off Websites trust bit for "Global Chambersign Root - 2008" |
Jan. 27, 2021 Alexey Gladkov 3.61.0-alt1 |
- New version (3.61).
- Certificate Authority Changes:
+ Add CN=NAVER Global Root Certification Authority
+ Remove CN=GeoTrust Global CA
+ Remove CN=GeoTrust Primary Certification Authority
+ Remove CN=GeoTrust Primary Certification Authority - G3
+ Remove CN=GeoTrust Universal CA
+ Remove CN=GeoTrust Universal CA 2
+ Remove CN=VeriSign Class 3 Public Primary Certification Authority - G4
+ Remove CN=VeriSign Class 3 Public Primary Certification Authority - G5
+ Remove CN=thawte Primary Root CA
+ Remove CN=thawte Primary Root CA - G2
+ Remove CN=thawte Primary Root CA - G3 |
Dec. 26, 2020 Alexey Gladkov 3.59.1-alt1 |
- New version (3.59.1). |
Nov. 17, 2020 Alexey Gladkov 3.59.0-alt1 |
- New version (3.59). |
Oct. 29, 2020 Stanislav Levin 3.58.0-alt2 |
- Backported fix for MBZ#1672703. |
Oct. 22, 2020 Alexey Gladkov 3.58.0-alt1 |
- New version (3.58).
- Security fixes:
+ CVE-2020-25648: Tighten CCS handling for middlebox compatibility mode
- Certificate Authority Changes:
+ Add CN=Trustwave Global Certification Authority
+ Add CN=Trustwave Global ECC P256 Certification Authority
+ Add CN=Trustwave Global ECC P384 Certification Authority
+ Remove CN=EE Certification Centre Root CA
+ Remove O=Government Root Certification Authority; C=TW
+ Modify CN=OISTE WISeKey Global Root GA CA |
Sept. 8, 2020 Alexey Gladkov 3.56.0-alt1 |
- New version (3.56). |
July 30, 2020 Alexey Gladkov 3.55.0-alt1 |
- New version (3.55).
- Security fixes:
+ CVE-2020-6829, CVE-2020-12400: Replace P384 and P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila.
+ CVE-2020-12401: Remove unnecessary scalar padding.
+ CVE-2020-12403: Explicitly disable multi-part ChaCha20 (which was not functioning correctly) and more strictly enforce tag length. |
June 29, 2020 Alexey Gladkov 3.54.0-alt1 |
- New version (3.54).
- Merge libnss and libnss-sysinit.
- Certificate Authority Changes:
+ Add CN = certSIGN Root CA G2
+ Add CN = e-Szigno Root CA 2017
+ Add CN = Microsoft ECC Root Certificate Authority 2017
+ Add CN = Microsoft RSA Root Certificate Authority 2017
+ Remove CN = AddTrust Class 1 CA Root
+ Remove CN = AddTrust External CA Root
+ Remove CN = LuxTrust Global Root 2
+ Remove CN = Staat der Nederlanden Root CA - G2
+ Remove CN = Symantec Class 2 Public Primary Certification Authority - G4
+ Remove CN = Symantec Class 1 Public Primary Certification Authority - G4
+ Remove CN = VeriSign Class 3 Public Primary Certification Authority - G3 |
June 24, 2020 Alexey Gladkov 3.53.0-alt4 |
- Enable an RFC3280 compliant certificate path validation library (ALT#38636). |
June 10, 2020 Alexey Gladkov 3.53.0-alt3 |
- Fix build with nss headers and -Werror=strict-prototypes (ALT#38597). |
June 8, 2020 Alexey Gladkov 3.53.0-alt2 |
- Enable NSS legacy DBM type (ALT#38590). |
June 4, 2020 Alexey Gladkov 3.53.0-alt1 |
- New version (3.53).
- Security fixes:
+ CVE-2020-12399 - Force a fixed length for DSA exponentiation |