|
The pkinit-nss module wasn't supplying a list of invalid certificates if
it encountered a revoked certificate.
|
|
The pkinit-nss module wasn't correctly encoding or decoding the typed-data
of most errors. It wasn't correctly encoding the public numbers of the DH key
agreement process correctly, either. It wasn't correctly comparing the size
of the client's DH prime against the configured minimum.
|