Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 311075 - Firefox client certificates don't work with dev-libs/openssl-0.9.8{l,m}
Summary: Firefox client certificates don't work with dev-libs/openssl-0.9.8{l,m}
Status: RESOLVED DUPLICATE of bug 304995
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High major
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-03-24 08:48 UTC by Lori
Modified: 2010-03-28 02:48 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lori 2010-03-24 08:48:06 UTC
After upgrading to dev-libs/openssl-0.9.8l-r2, I'm unable to use client certificates in Firefox to authenticate to web sites requiring them. At least the l version disabled SSL renegotiation as a workaround to the recent OpenSSL vulnerability, but m was supposed to fix it. It doesn't seem to be the case, and the ChangLog wasn't helpful enough to be sure. So I have to keep version k on clients and servers to keep certificate authentication functional, which for me is more important than the rather theoretical vulnerability.

I think version k should have stayed in Portage, even if hard masked with a message exaplaining the risks, for those who need it, until renegotiation works again.

Thanks!

Reproducible: Always

Steps to Reproduce:
Comment 1 Doktor Notor 2010-03-24 08:52:22 UTC
Likely a duplicate Bug 304995
Comment 2 Samuli Suominen (RETIRED) gentoo-dev 2010-03-24 11:00:10 UTC

*** This bug has been marked as a duplicate of bug 304995 ***
Comment 3 Jory A. Pratt gentoo-dev 2010-03-28 02:48:18 UTC
Lori just for future reference mozilla products use nss not openssl for its secure socket layer. This is where the breakage is has nothing to with with openssl if you can still duplicate this bug with nss-3.12.6 please comment on the nss bug to let us know. I will also be posting a request there as well.