Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: dev-libs/nss-3.29.5 security level problem?
Date: Thu, 10 May 2018 10:19:20
Message-Id: 6483030.j6tcS3DRs0@dell_xps
In Reply to: [gentoo-user] dev-libs/nss-3.29.5 security level problem? by Mick
1 On Thursday, 10 May 2018 10:48:06 BST Mick wrote:
2 > Hi All,
3 >
4 > I just discovered the last nss update broke things completely on mozilla
5 > apps which use nss. Firefox now refuses to connect to any site with https.
6 > Trying to load google.com brings up this error message:
7 >
8 > =============================
9 > Your connection is not secure
10 >
11 > The website tried to negotiate an inadequate level of security.
12 >
13 > www.google.com uses security technology that is outdated and vulnerable to
14 > attack. An attacker could easily reveal information which you thought to be
15 > safe. The website administrator will need to fix the server first before you
16 > can visit the site.
17 >
18 > Error code: NS_ERROR_NET_INADEQUATE_SECURITY
19 > ============================================
20 >
21 > Have you noticed the same?
22
23 OK, looking further into this problem, it was not an update, but a downgrade
24 which caused it. I had previously keyworded nss-3.36 which yesterday fell off
25 the tree and portage downgraded nss to 3.29.5. I keyworded and emerge 3.37
26 and all works as it should again. :-)
27
28 --
29 Regards,
30 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature