Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(349)

Side by Side Diff: components/policy/resources/policy_templates.json

Issue 1150373002: platformKeys: Add policy and corporate key tagging. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@key_perm
Patch Set: Rebased. Created 5 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « chrome/test/data/policy/policy_test_cases.json ('k') | tools/metrics/histograms/histograms.xml » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 { 1 {
2 # policy_templates.json - Metafile for policy templates 2 # policy_templates.json - Metafile for policy templates
3 # 3 #
4 # The content of this file is evaluated as a Python expression. 4 # The content of this file is evaluated as a Python expression.
5 # 5 #
6 # This file is used as input to generate the following policy templates: 6 # This file is used as input to generate the following policy templates:
7 # ADM, ADMX+ADML, MCX/plist and html documentation. 7 # ADM, ADMX+ADML, MCX/plist and html documentation.
8 # 8 #
9 # Policy templates are user interface definitions or documents about the 9 # Policy templates are user interface definitions or documents about the
10 # policies that can be used to configure Chrome. Each policy is a name-value 10 # policies that can be used to configure Chrome. Each policy is a name-value
(...skipping 105 matching lines...) Expand 10 before | Expand all | Expand 10 after
116 # templates and documentation. The policy definition list that Chrome sees 116 # templates and documentation. The policy definition list that Chrome sees
117 # will include policies marked with 'future'. If a WIP policy isn't meant to 117 # will include policies marked with 'future'. If a WIP policy isn't meant to
118 # be seen by the policy providers either, the 'supported_on' key should be set 118 # be seen by the policy providers either, the 'supported_on' key should be set
119 # to an empty list. 119 # to an empty list.
120 # 120 #
121 # IDs: 121 # IDs:
122 # Since a Protocol Buffer definition is generated from this file, unique and 122 # Since a Protocol Buffer definition is generated from this file, unique and
123 # persistent IDs for all fields (but not for groups!) are needed. These are 123 # persistent IDs for all fields (but not for groups!) are needed. These are
124 # specified by the 'id' keys of each policy. NEVER CHANGE EXISTING IDs, 124 # specified by the 'id' keys of each policy. NEVER CHANGE EXISTING IDs,
125 # because doing so would break the deployed wire format! 125 # because doing so would break the deployed wire format!
126 # For your editing convenience: highest ID currently used: 301 126 # For your editing convenience: highest ID currently used: 302
127 # 127 #
128 # Placeholders: 128 # Placeholders:
129 # The following placeholder strings are automatically substituted: 129 # The following placeholder strings are automatically substituted:
130 # $1 -> Google Chrome / Chromium 130 # $1 -> Google Chrome / Chromium
131 # $2 -> Google Chrome OS / Chromium OS 131 # $2 -> Google Chrome OS / Chromium OS
132 # $3 -> Google Chrome Frame / Chromium Frame 132 # $3 -> Google Chrome Frame / Chromium Frame
133 # $6 is reserved for doc_writer 133 # $6 is reserved for doc_writer
134 # 134 #
135 # Device Policy: 135 # Device Policy:
136 # An additional flag device_only (optional, defaults to False) indicates 136 # An additional flag device_only (optional, defaults to False) indicates
(...skipping 7213 matching lines...) Expand 10 before | Expand all | Expand 10 after
7350 'features': { 7350 'features': {
7351 'dynamic_refresh': False, 7351 'dynamic_refresh': False,
7352 'per_profile': False, 7352 'per_profile': False,
7353 }, 7353 },
7354 'example_value': True, 7354 'example_value': True,
7355 'id': 301, 7355 'id': 301,
7356 'caption': '''Allows QUIC protocol''', 7356 'caption': '''Allows QUIC protocol''',
7357 'desc': '''If this policy is set to true or not set usage of QUIC protocol in <ph name="PRODUCT_NAME">$1<ex>Google Chrome</ex></ph> is allowed. 7357 'desc': '''If this policy is set to true or not set usage of QUIC protocol in <ph name="PRODUCT_NAME">$1<ex>Google Chrome</ex></ph> is allowed.
7358 If this policy is set to false usage of QUIC protocol is disallowed.''', 7358 If this policy is set to false usage of QUIC protocol is disallowed.''',
7359 }, 7359 },
7360 {
7361 'name': 'KeyPermissions',
7362 'type': 'dict',
7363 'schema': {
7364 'type': 'object',
7365 'additionalProperties': {
7366 'type': 'object',
7367 'properties': {
7368 'allowCorporateKeyUsage': {
7369 'description': '''If set to true, this extension can use all keys that are designated for corporate usage to sign arbitrary data. If set to false, it cannot access any such keys and the user cannot grant such permission either .''',
7370 'type': 'boolean',
7371 },
7372 },
7373 },
7374 },
7375 'supported_on': ['chrome_os:45-'],
7376 'features': {
7377 'dynamic_refresh': True,
7378 'per_profile': True,
7379 },
7380 'example_value': {
7381 'extension1': {
7382 'allowCorporateKeyUsage': 'true'
7383 },
7384 'extension2': {
7385 'allowCorporateKeyUsage': 'false'
7386 }
7387 },
7388 'id': 302,
7389 'caption': 'Key Permissions',
7390 'desc': '''Grants access to corporate keys to extensions.
7360 7391
7392 Keys are designated for corporate usage if they're generated using the chr ome.platformKeys API on a managed account. Keys imported or generated in another way are not designated for corporate usage.
7393
7394 Access to keys designated for corporate usage is solely controlled by this policy. The user can neither grant nor withdraw access to corporate keys to or from extensions.
7395
7396 By default an extension cannot use a key designated for corporate usage, w hich is equivalent to setting allowCorporateKeyUsage to false for that extension .
7397
7398 Only if allowCorporateKeyUsage is set to true for an extension, it can use any platform key marked for corporate usage to sign arbitrary data. This permis sion should only be granted if the extension is trusted to secure access to the key against attackers.''',
7399 },
7361 ], 7400 ],
7362 'messages': { 7401 'messages': {
7363 # Messages that are not associated to any policies. 7402 # Messages that are not associated to any policies.
7364 'win_supported_winxpsp2': { 7403 'win_supported_winxpsp2': {
7365 'desc': '''A label specifying the oldest possible compatible version of Wi ndows. This text will appear right next to a label containing the text 'Supporte d on:'.''', 7404 'desc': '''A label specifying the oldest possible compatible version of Wi ndows. This text will appear right next to a label containing the text 'Supporte d on:'.''',
7366 'text': '''Microsoft Windows XP SP2 or later''' 7405 'text': '''Microsoft Windows XP SP2 or later'''
7367 }, 7406 },
7368 'mac_chrome_preferences': { 7407 'mac_chrome_preferences': {
7369 'desc': '''A text indicating in Mac OS X Workgroup Manager, that currently the preferences of Chromium are being edited''', 7408 'desc': '''A text indicating in Mac OS X Workgroup Manager, that currently the preferences of Chromium are being edited''',
7370 'text': '''<ph name="PRODUCT_NAME">$1<ex>Google Chrome</ex></ph> preferenc es''' 7409 'text': '''<ph name="PRODUCT_NAME">$1<ex>Google Chrome</ex></ph> preferenc es'''
(...skipping 105 matching lines...) Expand 10 before | Expand all | Expand 10 after
7476 'desc': '''Text appended in parentheses next to the policies top-level con tainer to indicate that those policies are of the Recommended level''', 7515 'desc': '''Text appended in parentheses next to the policies top-level con tainer to indicate that those policies are of the Recommended level''',
7477 'text': 'Default Settings (users can override)', 7516 'text': 'Default Settings (users can override)',
7478 }, 7517 },
7479 'doc_complex_policies_on_windows': { 7518 'doc_complex_policies_on_windows': {
7480 'desc': '''Text pointing the user to a help article for complex policies o n Windows''', 7519 'desc': '''Text pointing the user to a help article for complex policies o n Windows''',
7481 'text': '''encoded as a JSON string, for details see <ph name="COMPLEX_POL ICIES_URL">http://www.chromium.org/administrators/complex-policies-on-windows<ex >http://www.chromium.org/administrators/complex-policies-on-windows</ex></ph>''' , 7520 'text': '''encoded as a JSON string, for details see <ph name="COMPLEX_POL ICIES_URL">http://www.chromium.org/administrators/complex-policies-on-windows<ex >http://www.chromium.org/administrators/complex-policies-on-windows</ex></ph>''' ,
7482 }, 7521 },
7483 }, 7522 },
7484 'placeholders': [], 7523 'placeholders': [],
7485 } 7524 }
OLDNEW
« no previous file with comments | « chrome/test/data/policy/policy_test_cases.json ('k') | tools/metrics/histograms/histograms.xml » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698