[tor-bugs] #29241 [Core Tor/Tor]: NSS SSL_ExportKeyingMaterial failing

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Mar 29 17:46:20 UTC 2019


#29241: NSS SSL_ExportKeyingMaterial failing
-------------------------------------------------+-------------------------
 Reporter:  sysrqb                               |          Owner:  nickm
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  High                                 |      Milestone:  Tor:
                                                 |  0.4.0.x-final
Component:  Core Tor/Tor                         |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  regression, 035-backport?,           |  Actual Points:  1.5
  040-must, spec                                 |
Parent ID:                                       |         Points:  2
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by nickm):

 * status:  accepted => needs_review
 * actualpoints:   => 1.5


Comment:

 Aha.  There is a bug (or a missing feature?) in NSS where you can't use
 `SSL_ExportKeyingMaterial()` with a TLS1.2 ciphersuite that uses SHA384 as
 its PRF hash: https://bugzilla.mozilla.org/show_bug.cgi?id=1312976 .

 See branch `ticket29241_040` with PR at
 https://github.com/torproject/tor/pull/869

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29241#comment:9>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list