Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(754)

Unified Diff: chrome/browser/chromeos/policy/network_configuration_updater_impl.cc

Issue 16946002: Resolve certificate references in ONC by PEM. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Added a unit test for the resolve function. Created 7 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/chromeos/policy/network_configuration_updater_impl.cc
diff --git a/chrome/browser/chromeos/policy/network_configuration_updater_impl.cc b/chrome/browser/chromeos/policy/network_configuration_updater_impl.cc
index 54e403331dd4cc0e51049da1904d3ca8f47a9834..5fa896cd6a6607c51ee83bf2c2955cc8cdcfdad8 100644
--- a/chrome/browser/chromeos/policy/network_configuration_updater_impl.cc
+++ b/chrome/browser/chromeos/policy/network_configuration_updater_impl.cc
@@ -97,15 +97,24 @@ void NetworkConfigurationUpdaterImpl::ApplyNetworkConfiguration(
ParseAndValidateOncForImport(
onc_blob, onc_source, "", &network_configs, &certificates);
+ chromeos::CertificateHandler::CertsByGUID imported_server_and_ca_certs;
+ scoped_ptr<net::CertificateList> web_trust_certs(new net::CertificateList);
+ certificate_handler_->ImportCertificates(
+ certificates, onc_source, web_trust_certs.get(),
+ &imported_server_and_ca_certs);
+
+ if (!chromeos::onc::ResolveServerCertRefsInNetworks(
+ imported_server_and_ca_certs, &network_configs)) {
+ LOG(ERROR) << "Some certificate references in the ONC policy for source "
+ << chromeos::onc::GetSourceAsString(onc_source)
+ << " could not be resolved.";
+ }
+
std::string userhash = onc_source == chromeos::onc::ONC_SOURCE_USER_POLICY ?
hashed_username_ : std::string();
chromeos::NetworkHandler::Get()->managed_network_configuration_handler()->
SetPolicy(onc_source, userhash, network_configs);
- scoped_ptr<net::CertificateList> web_trust_certs(new net::CertificateList);
- certificate_handler_->ImportCertificates(
- certificates, onc_source, web_trust_certs.get());
-
if (onc_source == chromeos::onc::ONC_SOURCE_USER_POLICY)
SetTrustAnchors(web_trust_certs.Pass());
}

Powered by Google App Engine
This is Rietveld 408576698