| Index: net/third_party/nss/patches/suitebonly.patch
|
| ===================================================================
|
| --- net/third_party/nss/patches/suitebonly.patch (revision 0)
|
| +++ net/third_party/nss/patches/suitebonly.patch (revision 0)
|
| @@ -0,0 +1,21 @@
|
| +diff -pu a/nss/lib/ssl/ssl3ecc.c b/nss/lib/ssl/ssl3ecc.c
|
| +--- a/nss/lib/ssl/ssl3ecc.c 2013-04-27 09:40:21.645984036 -0700
|
| ++++ b/nss/lib/ssl/ssl3ecc.c 2013-04-27 09:42:14.977586966 -0700
|
| +@@ -1031,6 +1031,7 @@ static const PRUint8 ECPtFmt[6] = {
|
| + static PRBool
|
| + ssl3_SuiteBOnly(sslSocket *ss)
|
| + {
|
| ++#if 0
|
| + /* look to see if we can handle certs less than 163 bits */
|
| + PK11SlotInfo *slot =
|
| + PK11_GetBestSlotWithAttributes(CKM_ECDH1_DERIVE, 0, 163,
|
| +@@ -1043,6 +1044,9 @@ ssl3_SuiteBOnly(sslSocket *ss)
|
| + /* we can, presume we can do all curves */
|
| + PK11_FreeSlot(slot);
|
| + return PR_FALSE;
|
| ++#else
|
| ++ return PR_TRUE;
|
| ++#endif
|
| + }
|
| +
|
| + /* Send our "canned" (precompiled) Supported Elliptic Curves extension,
|
|
|