[tor-bugs] #27288 [Core Tor/Tor]: Tor with NSS must not claim to support LinkAuth=1

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 23 15:29:56 UTC 2018


#27288: Tor with NSS must not claim to support LinkAuth=1
-------------------------+-------------------------------------------------
     Reporter:  nickm    |      Owner:  (none)
         Type:  defect   |     Status:  new
     Priority:  Medium   |  Milestone:  Tor: 0.3.5.x-final
    Component:  Core     |    Version:
  Tor/Tor                |   Keywords:  035-roadmap-master, 035-triaged-
     Severity:  Normal   |  in-20180711
Actual Points:           |  Parent ID:  #26631
       Points:           |   Reviewer:
      Sponsor:           |
  Sponsor8               |
-------------------------+-------------------------------------------------
 LinkAuth=1 is the older one that pokes inside the world of TLS master
 secrets. NSS sensibly doesn't let us do that, and makes us use RFC5705
 like sensible people.

 We shouldn't claim to support it, though.

 I'm making this a separate ticket from the rest of NSS-TLS, though, since
 once we merge this, Tor clients and servers will stop working with NSS
 until #27286 is merged to update the list of required protocols.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27288>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list