| OLD | NEW |
| 1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "net/cert/cert_status_flags.h" | 5 #include "net/cert/cert_status_flags.h" |
| 6 | 6 |
| 7 #include "base/logging.h" | 7 #include "base/logging.h" |
| 8 #include "net/base/net_errors.h" | 8 #include "net/base/net_errors.h" |
| 9 | 9 |
| 10 namespace net { | 10 namespace net { |
| (...skipping 29 matching lines...) Expand all Loading... |
| 40 case ERR_CERT_INVALID: | 40 case ERR_CERT_INVALID: |
| 41 return CERT_STATUS_INVALID; | 41 return CERT_STATUS_INVALID; |
| 42 case ERR_CERT_WEAK_SIGNATURE_ALGORITHM: | 42 case ERR_CERT_WEAK_SIGNATURE_ALGORITHM: |
| 43 return CERT_STATUS_WEAK_SIGNATURE_ALGORITHM; | 43 return CERT_STATUS_WEAK_SIGNATURE_ALGORITHM; |
| 44 case ERR_CERT_NON_UNIQUE_NAME: | 44 case ERR_CERT_NON_UNIQUE_NAME: |
| 45 return CERT_STATUS_NON_UNIQUE_NAME; | 45 return CERT_STATUS_NON_UNIQUE_NAME; |
| 46 case ERR_CERT_WEAK_KEY: | 46 case ERR_CERT_WEAK_KEY: |
| 47 return CERT_STATUS_WEAK_KEY; | 47 return CERT_STATUS_WEAK_KEY; |
| 48 case ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN: | 48 case ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN: |
| 49 return CERT_STATUS_PINNED_KEY_MISSING; | 49 return CERT_STATUS_PINNED_KEY_MISSING; |
| 50 case ERR_SSL_WEAK_SERVER_EPHEMERAL_DH_KEY: | |
| 51 return CERT_STATUS_WEAK_DH_KEY; | |
| 52 case ERR_CERT_NAME_CONSTRAINT_VIOLATION: | 50 case ERR_CERT_NAME_CONSTRAINT_VIOLATION: |
| 53 return CERT_STATUS_NAME_CONSTRAINT_VIOLATION; | 51 return CERT_STATUS_NAME_CONSTRAINT_VIOLATION; |
| 54 default: | 52 default: |
| 55 return 0; | 53 return 0; |
| 56 } | 54 } |
| 57 } | 55 } |
| 58 | 56 |
| 59 int MapCertStatusToNetError(CertStatus cert_status) { | 57 int MapCertStatusToNetError(CertStatus cert_status) { |
| 60 // A certificate may have multiple errors. We report the most | 58 // A certificate may have multiple errors. We report the most |
| 61 // serious error. | 59 // serious error. |
| 62 | 60 |
| 63 // Unrecoverable errors | 61 // Unrecoverable errors |
| 64 if (cert_status & CERT_STATUS_REVOKED) | 62 if (cert_status & CERT_STATUS_REVOKED) |
| 65 return ERR_CERT_REVOKED; | 63 return ERR_CERT_REVOKED; |
| 66 if (cert_status & CERT_STATUS_INVALID) | 64 if (cert_status & CERT_STATUS_INVALID) |
| 67 return ERR_CERT_INVALID; | 65 return ERR_CERT_INVALID; |
| 68 if (cert_status & CERT_STATUS_PINNED_KEY_MISSING) | 66 if (cert_status & CERT_STATUS_PINNED_KEY_MISSING) |
| 69 return ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN; | 67 return ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN; |
| 70 if (cert_status & CERT_STATUS_WEAK_DH_KEY) | |
| 71 return ERR_SSL_WEAK_SERVER_EPHEMERAL_DH_KEY; | |
| 72 | 68 |
| 73 // Recoverable errors | 69 // Recoverable errors |
| 74 if (cert_status & CERT_STATUS_AUTHORITY_INVALID) | 70 if (cert_status & CERT_STATUS_AUTHORITY_INVALID) |
| 75 return ERR_CERT_AUTHORITY_INVALID; | 71 return ERR_CERT_AUTHORITY_INVALID; |
| 76 if (cert_status & CERT_STATUS_COMMON_NAME_INVALID) | 72 if (cert_status & CERT_STATUS_COMMON_NAME_INVALID) |
| 77 return ERR_CERT_COMMON_NAME_INVALID; | 73 return ERR_CERT_COMMON_NAME_INVALID; |
| 78 // CERT_STATUS_NON_UNIQUE_NAME is intentionally not mapped to an error. | 74 // CERT_STATUS_NON_UNIQUE_NAME is intentionally not mapped to an error. |
| 79 // It is treated as just a warning and used to degrade the SSL UI. | 75 // It is treated as just a warning and used to degrade the SSL UI. |
| 80 if (cert_status & CERT_STATUS_NAME_CONSTRAINT_VIOLATION) | 76 if (cert_status & CERT_STATUS_NAME_CONSTRAINT_VIOLATION) |
| 81 return ERR_CERT_NAME_CONSTRAINT_VIOLATION; | 77 return ERR_CERT_NAME_CONSTRAINT_VIOLATION; |
| 82 if (cert_status & CERT_STATUS_WEAK_SIGNATURE_ALGORITHM) | 78 if (cert_status & CERT_STATUS_WEAK_SIGNATURE_ALGORITHM) |
| 83 return ERR_CERT_WEAK_SIGNATURE_ALGORITHM; | 79 return ERR_CERT_WEAK_SIGNATURE_ALGORITHM; |
| 84 if (cert_status & CERT_STATUS_WEAK_KEY) | 80 if (cert_status & CERT_STATUS_WEAK_KEY) |
| 85 return ERR_CERT_WEAK_KEY; | 81 return ERR_CERT_WEAK_KEY; |
| 86 if (cert_status & CERT_STATUS_DATE_INVALID) | 82 if (cert_status & CERT_STATUS_DATE_INVALID) |
| 87 return ERR_CERT_DATE_INVALID; | 83 return ERR_CERT_DATE_INVALID; |
| 88 | 84 |
| 89 // Unknown status. Give it the benefit of the doubt. | 85 // Unknown status. Give it the benefit of the doubt. |
| 90 if (cert_status & CERT_STATUS_UNABLE_TO_CHECK_REVOCATION) | 86 if (cert_status & CERT_STATUS_UNABLE_TO_CHECK_REVOCATION) |
| 91 return ERR_CERT_UNABLE_TO_CHECK_REVOCATION; | 87 return ERR_CERT_UNABLE_TO_CHECK_REVOCATION; |
| 92 if (cert_status & CERT_STATUS_NO_REVOCATION_MECHANISM) | 88 if (cert_status & CERT_STATUS_NO_REVOCATION_MECHANISM) |
| 93 return ERR_CERT_NO_REVOCATION_MECHANISM; | 89 return ERR_CERT_NO_REVOCATION_MECHANISM; |
| 94 | 90 |
| 95 NOTREACHED(); | 91 NOTREACHED(); |
| 96 return ERR_UNEXPECTED; | 92 return ERR_UNEXPECTED; |
| 97 } | 93 } |
| 98 | 94 |
| 99 } // namespace net | 95 } // namespace net |
| OLD | NEW |