-
Bug
-
Resolution: Done-Errata
-
Normal
-
rhel-10.0.z, rhel-9.7
-
No
-
Low
-
2
-
rhel-security-crypto-clubs
-
1.5
-
False
-
False
-
-
No
-
Crypto25August, Crypto25September
-
-
Pass
-
Automated
-
Unspecified Release Note Type - Unknown
-
Unspecified
-
Unspecified
-
Unspecified
-
-
s390x
-
None
What were you trying to do that didn't work?
Use zlib certificate compression with tstclnt/selfserv on s390x.
What is the impact of this issue to you?
I try to not attach personally to such stuff, but that leaves cert compression as implemented in NSS broken on big-endian platforms.
Please provide the package NVR for which the bug is seen:
nss-3.112.0-2.el10_0
How reproducible is this bug?:
reliably
Steps to reproduce
- selfserv -n server -d sql:nssdb -q -p 4433
- connect with openssl, gnutls or tlsfuzzer's test-tls13-certificate-compression.py
Expected results
cert compression works
Actual results
handshake_failed alerts from NSS
Fix
- is triggered by
-
RHEL-57787 Selfserv -q flag is not enabling compressed certificate support
-
- Release Pending
-
- links to
-
RHEA-2025:152258 nss enhancement update