For compatibility reasons it may be desirable to allow non-FIPS ciphers in some cases even while in FIPs mode. Add an option to not be so strict about FIPS ciphers-only when NSSFIPS is on.
I'm not sure what was going through my head when I opened this, thinking this was a good idea.
Either an algortihm is FIPS-approved or it isn't. There is no way to claim FIPS compliance and allow un-approved ciphers to be enabled. It may even be (and probably is) that NSS would reject the ciphers as well (I know it does with MD5 for example).
So I'm just going to close this as won't fix because it's a just a bad idea.
Metadata Update from @rcritten: - Issue close_status updated to: wontfix - Issue priority set to: None (was: 3) - Issue status updated to: Closed (was: Open)