Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(197)

Issue 2155753002: Enable Expect-Staple in SSLClientSocket. (Closed)

Created:
4 years, 5 months ago by dadrian
Modified:
4 years, 5 months ago
Reviewers:
svaldez, Ryan Sleevi, estark
CC:
chromium-reviews, cbentzel+watch_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@ocsp-reporting
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Enable Expect-Staple in SSLClientSocket. In TransportSecurityState, set |enable_static_expect_staple_| to true by default. Update SSLClientSocket to call TransportSecurityState::ProcessExpectStaple. In ssl_client_socket_impl.cc, this also removes the if (|signed_certificate_timestamps_enabled_) check around extracting the OCSP response and setting the UMA_HISTOGRAM_BOOLEAN("Net.OCSPResponseStapled"). Since SCTs are always enabled, this if statement was a noop. This does not enable Expect-Staple for QUIC. See https://crbug.com/631101 BUG=598021 Committed: https://crrev.com/3c0e49240847ea54265e17c7a8a1ecf73daeaeee Cr-Commit-Position: refs/heads/master@{#407575}

Patch Set 1 #

Patch Set 2 : Enable by default #

Total comments: 1

Patch Set 3 : Rebase / Add QUIC todo #

Unified diffs Side-by-side diffs Delta from patch set Stats (+134 lines, -36 lines) Patch
M net/http/transport_security_state.cc View 1 2 1 chunk +1 line, -1 line 0 comments Download
M net/http/transport_security_state_unittest.cc View 1 2 7 chunks +10 lines, -8 lines 0 comments Download
M net/quic/quic_crypto_client_stream.cc View 1 2 1 chunk +1 line, -0 lines 0 comments Download
M net/socket/ssl_client_socket_impl.h View 1 1 chunk +1 line, -0 lines 0 comments Download
M net/socket/ssl_client_socket_impl.cc View 1 2 5 chunks +15 lines, -27 lines 0 comments Download
M net/url_request/url_request_unittest.cc View 1 2 chunks +106 lines, -0 lines 0 comments Download

Messages

Total messages: 23 (8 generated)
dadrian
Sending this out for review now that the depends-on are in the CQ / committed. ...
4 years, 5 months ago (2016-07-20 23:37:19 UTC) #3
Ryan Sleevi
Small question: Why not QUIC too?
4 years, 5 months ago (2016-07-20 23:46:35 UTC) #4
dadrian
On 2016/07/20 23:46:35, Ryan Sleevi (extremely slow) wrote: > Small question: Why not QUIC too? ...
4 years, 5 months ago (2016-07-20 23:48:59 UTC) #5
svaldez
You'll probably want to add a bug or TODO for supporting Expect-Staple with QUIC, at ...
4 years, 5 months ago (2016-07-25 14:57:39 UTC) #6
chromium-reviews
On Jul 25, 2016 7:57 AM, <svaldez@chromium.org> wrote: > > > > > https://codereview.chromium.org/2155753002/diff/20001/net/socket/ssl_client_socket_impl.cc > ...
4 years, 5 months ago (2016-07-25 15:10:33 UTC) #7
dadrian
TODO added, description updated.
4 years, 5 months ago (2016-07-25 17:39:47 UTC) #9
Ryan Sleevi
LGTM but wouldn't mind a secondary spot-check from estark or svaldez
4 years, 5 months ago (2016-07-25 18:31:42 UTC) #10
svaldez
Consider adding the QUIC bug to the CL description, though maybe not necessary. LGTM otherwise.
4 years, 5 months ago (2016-07-25 19:11:23 UTC) #11
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2155753002/40001
4 years, 5 months ago (2016-07-25 20:08:20 UTC) #14
commit-bot: I haz the power
Committed patchset #3 (id:40001)
4 years, 5 months ago (2016-07-25 21:17:22 UTC) #16
commit-bot: I haz the power
Patchset 3 (id:??) landed as https://crrev.com/3c0e49240847ea54265e17c7a8a1ecf73daeaeee Cr-Commit-Position: refs/heads/master@{#407575}
4 years, 5 months ago (2016-07-25 21:19:59 UTC) #18
xunjieli
net_unittests is failing on a Cronet bot. This is the ssl-related change in the range. ...
4 years, 5 months ago (2016-07-25 21:48:35 UTC) #20
Mark P
The tree is closed. To reopen the tree, I will revert this change.
4 years, 5 months ago (2016-07-25 21:54:32 UTC) #21
Mark P
A revert of this CL (patchset #3 id:40001) has been created in https://codereview.chromium.org/2176183003/ by mpearson@chromium.org. ...
4 years, 5 months ago (2016-07-25 21:56:34 UTC) #22
findit-for-me
4 years, 5 months ago (2016-07-25 22:19:02 UTC) #23
Message was sent while issue was closed.
FYI: Findit try jobs (rerunning failed compile or tests) identified this CL
at revision 407575 as the culprit for failures in the build cycles as shown on:
https://findit-for-me.appspot.com/waterfall/culprit?key=ag9zfmZpbmRpdC1mb3Itb...

Powered by Google App Engine
This is Rietveld 408576698