GNU bug report logs - #32833
IceCat 60 certificate validation fails when using system NSS

Previous Next

Package: guix;

Reported by: Mike Gerwitz <mtg <at> gnu.org>

Date: Tue, 25 Sep 2018 04:30:02 UTC

Severity: normal

Done: Maxim Cournoyer <maxim.cournoyer <at> gmail.com>

Bug is archived. No further changes may be made.

Full log


Message #16 received at 32833 <at> debbugs.gnu.org (full text, mbox):

From: Mike Gerwitz <mtg <at> gnu.org>
To: Mark H Weaver <mhw <at> netris.org>
Cc: 32833 <at> debbugs.gnu.org
Subject: Re: bug#32833: IceCat 60 showing sites as "insecure" despite using
 HTTPS
Date: Tue, 25 Sep 2018 20:30:57 -0400
[Message part 1 (text/plain, inline)]
On Tue, Sep 25, 2018 at 20:16:16 -0400, Mark H Weaver wrote:
> Mark H Weaver <mhw <at> netris.org> writes:
>> To begin, I'm currently building IceCat using the bundled NSPR and NSS,
>> to see if that helps.
>
> Using the bundled NSPR and NSS works around the problem for me.  I just
> pushed this change in commit 6d328879378fac95240005233331f596fb5c68ed on
> 'master'.  See also the related, immediately preceding commits
> 257e3247910610fe24ae1b86f38e85552d53e48c and
> 94e96f7f68c3b9053fdb5dee5b0ab614163aaa08.

Great!

> I'm keeping this bug report open, since it would be good to find a
> better fix which avoids using the bundled libraries.

I wish I knew enough to suggest a better solution.

It's a little late now, but I just tested the IceCat binary on a Debian
machine and HTTPS works as expected.

Thanks again for your work on this.  Maybe I'll let IceCat build
overnight so I can give it a try tomorrow (still on my X200).

-- 
Mike Gerwitz
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 1 year and 264 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.