{"affected":[{"ecosystem_specific":{"binaries":[{"apache2-mod_nss":"1.0.14-10.17.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"apache2-mod_nss","purl":"pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.14-10.17.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for apache2-mod_nss fixes the following issues:\n\nDue to the update of mozilla-nss apache2-mod_nss needs to be updated to change\nto the SQLite certificate database, which is now the default (bsc#1108771).\nBecause of that this update is tagged as security, to reach customers that only\ninstall secuirty updates.\n\nOther changes contained:\n\n- Require minimal NSS version of 3.25 because of SSLv2 changes (bsc#993642)\n- Add support for SHA384 TLS ciphers (bsc#863035)\n- Remove deprecated NSSSessionCacheTimeout option from mod_nss.conf.in (bsc#998176)\n- Change ownership of the gencert generated NSS database so apache can read it (bsc#998180)\n- Use correct configuration path in mod_nss.conf.in (bsc#996282)\n- Generate dummy certificates if there aren't any in mod_nss.d (bsc#998183)\n","id":"SUSE-SU-2018:3572-1","modified":"2018-10-30T12:31:24Z","published":"2018-10-30T12:31:24Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183572-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108771"},{"type":"REPORT","url":"https://bugzilla.suse.com/863035"},{"type":"REPORT","url":"https://bugzilla.suse.com/993642"},{"type":"REPORT","url":"https://bugzilla.suse.com/996282"},{"type":"REPORT","url":"https://bugzilla.suse.com/998176"},{"type":"REPORT","url":"https://bugzilla.suse.com/998180"},{"type":"REPORT","url":"https://bugzilla.suse.com/998183"}],"related":[],"summary":"Security update for apache2-mod_nss","upstream":[]}