Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(291)

Issue 2052363002: Enable public key pinning of local trust anchors (Closed)

Created:
4 years, 6 months ago by kapishnikov
Modified:
4 years, 5 months ago
Reviewers:
mef, Ryan Sleevi, xunjieli
CC:
chromium-reviews, cbentzel+watch_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Enable public key pinning of local trust anchors Provides a new API that allows Cronet client to enable public key pinning of local trust anchors, i.e. pinning of certificates added to the local user trust store. /** * Enables or disables pinning of the local (user-level) trust anchors. * * @param value {@code true} to enable pinning, {@code false} to disable. * @return the builder to facilitate chaining. */ public Builder enablePublicKeyPinsForLocalTrustAnchors(boolean value); BUG=606832 Committed: https://crrev.com/9cf8e6f923a9b472c8b3521d52b3b6ca910f77cf Committed: https://crrev.com/385aa4234b65c226458700c8c622d705c95eab50 Cr-Original-Commit-Position: refs/heads/master@{#403486} Cr-Commit-Position: refs/heads/master@{#403521}

Patch Set 1 #

Total comments: 10

Patch Set 2 : Addressed Ryan's comments + unit tests #

Total comments: 16

Patch Set 3 : Ryan's comments + use PKPStatus enum #

Patch Set 4 : url_request_context_config_unittest fix #

Total comments: 8

Patch Set 5 : Addressed Ryan's comments #

Patch Set 6 : Fixed CronetPerfTestActivity test #

Unified diffs Side-by-side diffs Delta from patch set Stats (+149 lines, -26 lines) Patch
M components/cronet/android/api/src/org/chromium/net/CronetEngine.java View 1 2 3 chunks +25 lines, -1 line 0 comments Download
M components/cronet/android/cronet_url_request_context_adapter.cc View 1 2 3 chunks +8 lines, -2 lines 0 comments Download
M components/cronet/android/java/src/org/chromium/net/CronetUrlRequestContext.java View 1 2 2 chunks +4 lines, -2 lines 0 comments Download
M components/cronet/android/test/cronet_url_request_context_config_test.cc View 1 2 1 chunk +1 line, -0 lines 0 comments Download
M components/cronet/android/test/javaperftests/src/org/chromium/net/CronetPerfTestActivity.java View 1 2 3 4 5 1 chunk +1 line, -1 line 0 comments Download
M components/cronet/android/test/javatests/src/org/chromium/net/CronetUrlRequestContextTest.java View 1 2 1 chunk +1 line, -0 lines 0 comments Download
M components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java View 1 2 3 4 17 chunks +65 lines, -6 lines 0 comments Download
M components/cronet/android/test/mock_cert_verifier.cc View 1 2 2 chunks +4 lines, -4 lines 0 comments Download
M components/cronet/android/test/src/org/chromium/net/MockCertVerifier.java View 1 1 chunk +4 lines, -3 lines 0 comments Download
M components/cronet/android/test/src/org/chromium/net/QuicTestServer.java View 1 1 chunk +1 line, -1 line 0 comments Download
M components/cronet/url_request_context_config.h View 1 2 2 chunks +6 lines, -1 line 0 comments Download
M components/cronet/url_request_context_config.cc View 1 2 2 chunks +5 lines, -2 lines 0 comments Download
M components/cronet/url_request_context_config_unittest.cc View 1 2 3 4 2 chunks +6 lines, -2 lines 0 comments Download
M net/http/transport_security_state.h View 1 2 3 4 5 2 chunks +11 lines, -0 lines 0 comments Download
M net/http/transport_security_state.cc View 1 2 3 4 5 3 chunks +7 lines, -1 line 0 comments Download

Messages

Total messages: 33 (13 generated)
kapishnikov
4 years, 6 months ago (2016-06-13 15:38:29 UTC) #3
Ryan Sleevi
https://codereview.chromium.org/2052363002/diff/1/components/cronet/android/api/src/org/chromium/net/CronetEngine.java File components/cronet/android/api/src/org/chromium/net/CronetEngine.java (right): https://codereview.chromium.org/2052363002/diff/1/components/cronet/android/api/src/org/chromium/net/CronetEngine.java#newcode105 components/cronet/android/api/src/org/chromium/net/CronetEngine.java:105: private boolean mPinLocalTrustAnchors = false; STYLE suggestion: Keep this ...
4 years, 6 months ago (2016-06-13 17:03:12 UTC) #4
kapishnikov
Ryan, thanks for the comments. I have added the unit tests. I will try to ...
4 years, 6 months ago (2016-06-15 00:56:20 UTC) #6
xunjieli
Sorry for the delay. I will take a look at the Cronet parts. The issue ...
4 years, 6 months ago (2016-06-20 16:54:52 UTC) #7
kapishnikov
On 2016/06/20 16:54:52, xunjieli wrote: > Sorry for the delay. I will take a look ...
4 years, 6 months ago (2016-06-20 17:11:19 UTC) #9
xunjieli
LGTM. one suggestion below. https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java File components/cronet/android/api/src/org/chromium/net/CronetEngine.java (right): https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java#newcode550 components/cronet/android/api/src/org/chromium/net/CronetEngine.java:550: public Builder enablePublicKeyPinsForLocalTrustAnchors(boolean value) { ...
4 years, 6 months ago (2016-06-20 21:50:49 UTC) #10
xunjieli
https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java File components/cronet/android/api/src/org/chromium/net/CronetEngine.java (right): https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java#newcode105 components/cronet/android/api/src/org/chromium/net/CronetEngine.java:105: private boolean mPublicKeyPinsForLocalTrustAnchorsEnabled = false; Suggest relying on the ...
4 years, 6 months ago (2016-06-20 21:54:53 UTC) #11
Ryan Sleevi
https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java File components/cronet/android/api/src/org/chromium/net/CronetEngine.java (right): https://codereview.chromium.org/2052363002/diff/20001/components/cronet/android/api/src/org/chromium/net/CronetEngine.java#newcode545 components/cronet/android/api/src/org/chromium/net/CronetEngine.java:545: * Enables or disables pinning of the local (user-level) ...
4 years, 6 months ago (2016-06-21 00:52:26 UTC) #12
kapishnikov
Ryan, Helen, thanks for the review comments. I think I have addressed them all. Also ...
4 years, 5 months ago (2016-06-29 23:04:32 UTC) #13
Ryan Sleevi
LGTM % nits https://codereview.chromium.org/2052363002/diff/60001/components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java File components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java (right): https://codereview.chromium.org/2052363002/diff/60001/components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java#newcode210 components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java:210: * Tests that the pinning of ...
4 years, 5 months ago (2016-07-01 01:17:24 UTC) #14
kapishnikov
https://codereview.chromium.org/2052363002/diff/60001/components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java File components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java (right): https://codereview.chromium.org/2052363002/diff/60001/components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java#newcode210 components/cronet/android/test/javatests/src/org/chromium/net/PkpTest.java:210: * Tests that the pinning of local trust anchors ...
4 years, 5 months ago (2016-07-01 17:20:55 UTC) #15
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2052363002/80001
4 years, 5 months ago (2016-07-01 17:21:19 UTC) #18
commit-bot: I haz the power
Committed patchset #5 (id:80001)
4 years, 5 months ago (2016-07-01 18:29:32 UTC) #20
commit-bot: I haz the power
CQ bit was unchecked.
4 years, 5 months ago (2016-07-01 18:29:49 UTC) #21
commit-bot: I haz the power
Patchset 5 (id:??) landed as https://crrev.com/9cf8e6f923a9b472c8b3521d52b3b6ca910f77cf Cr-Commit-Position: refs/heads/master@{#403486}
4 years, 5 months ago (2016-07-01 18:32:56 UTC) #23
kelvinp
A revert of this CL (patchset #5 id:80001) has been created in https://codereview.chromium.org/2117763004/ by kelvinp@chromium.org. ...
4 years, 5 months ago (2016-07-01 19:21:24 UTC) #24
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2052363002/100001
4 years, 5 months ago (2016-07-01 20:32:00 UTC) #28
commit-bot: I haz the power
Committed patchset #6 (id:100001)
4 years, 5 months ago (2016-07-01 20:53:16 UTC) #30
commit-bot: I haz the power
CQ bit was unchecked.
4 years, 5 months ago (2016-07-01 20:53:19 UTC) #31
commit-bot: I haz the power
4 years, 5 months ago (2016-07-01 20:54:45 UTC) #33
Message was sent while issue was closed.
Patchset 6 (id:??) landed as
https://crrev.com/385aa4234b65c226458700c8c622d705c95eab50
Cr-Commit-Position: refs/heads/master@{#403521}

Powered by Google App Engine
This is Rietveld 408576698