Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(214)

Side by Side Diff: net/http/transport_security_state_static.json

Issue 23523016: net: don't allow SSLv3 fallback for Google properties. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Created 7 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
« no previous file with comments | « net/http/transport_security_state_static.h ('k') | no next file » | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 // This file contains the HSTS preloaded list in a machine readable format. 5 // This file contains the HSTS preloaded list in a machine readable format.
6 6
7 // The top-level element is a dictionary with two keys: "pinsets" maps details 7 // The top-level element is a dictionary with two keys: "pinsets" maps details
8 // of certificate pinning to a name and "entries" contains the HSTS details for 8 // of certificate pinning to a name and "entries" contains the HSTS details for
9 // each host. 9 // each host.
10 // 10 //
(...skipping 183 matching lines...) Expand 10 before | Expand all | Expand 10 after
194 { "name": "codereview.chromium.org", "include_subdomains": true, "mode": "fo rce-https", "pins": "google" }, 194 { "name": "codereview.chromium.org", "include_subdomains": true, "mode": "fo rce-https", "pins": "google" },
195 { "name": "code.google.com", "include_subdomains": true, "mode": "force-http s", "pins": "google" }, 195 { "name": "code.google.com", "include_subdomains": true, "mode": "force-http s", "pins": "google" },
196 { "name": "googlecode.com", "include_subdomains": true, "pins": "google" }, 196 { "name": "googlecode.com", "include_subdomains": true, "pins": "google" },
197 { "name": "dl.google.com", "include_subdomains": true, "mode": "force-https" , "pins": "google" }, 197 { "name": "dl.google.com", "include_subdomains": true, "mode": "force-https" , "pins": "google" },
198 { "name": "translate.googleapis.com", "include_subdomains": true, "mode": "f orce-https", "pins": "google" }, 198 { "name": "translate.googleapis.com", "include_subdomains": true, "mode": "f orce-https", "pins": "google" },
199 199
200 // chart.apis.google.com is *not* HSTS because the certificate doesn't match 200 // chart.apis.google.com is *not* HSTS because the certificate doesn't match
201 // and there are lots of links out there that still use the name. The correc t 201 // and there are lots of links out there that still use the name. The correc t
202 // hostname for this is chart.googleapis.com. 202 // hostname for this is chart.googleapis.com.
203 { "name": "chart.apis.google.com", "include_subdomains": true, "pins": "goog le" }, 203 { "name": "chart.apis.google.com", "include_subdomains": true, "pins": "goog le" },
204 { "name": "oraprodsso.corp.google.com", "include_subdomains": true, "mode": "force-https" },
wtc 2013/09/03 18:17:16 It seems that include_subdomains should be false.
palmer 2013/09/03 18:20:45 agl probably intends to be defensive, and it makes
204 205
205 // Other Google-related domains that must use an acceptable certificate 206 // Other Google-related domains that must use an acceptable certificate
206 // iff using SSL. 207 // iff using SSL.
207 { "name": "ytimg.com", "include_subdomains": true, "pins": "google" }, 208 { "name": "ytimg.com", "include_subdomains": true, "pins": "google" },
208 { "name": "googleusercontent.com", "include_subdomains": true, "pins": "goog le" }, 209 { "name": "googleusercontent.com", "include_subdomains": true, "pins": "goog le" },
209 { "name": "youtube.com", "include_subdomains": true, "pins": "google" }, 210 { "name": "youtube.com", "include_subdomains": true, "pins": "google" },
210 { "name": "googleapis.com", "include_subdomains": true, "pins": "google" }, 211 { "name": "googleapis.com", "include_subdomains": true, "pins": "google" },
211 { "name": "googleadservices.com", "include_subdomains": true, "pins": "googl e" }, 212 { "name": "googleadservices.com", "include_subdomains": true, "pins": "googl e" },
212 { "name": "appspot.com", "include_subdomains": true, "pins": "google" }, 213 { "name": "appspot.com", "include_subdomains": true, "pins": "google" },
213 { "name": "googlesyndication.com", "include_subdomains": true, "pins": "goog le" }, 214 { "name": "googlesyndication.com", "include_subdomains": true, "pins": "goog le" },
(...skipping 420 matching lines...) Expand 10 before | Expand all | Expand 10 after
634 635
635 // Entries that are only valid if the client supports SNI. 636 // Entries that are only valid if the client supports SNI.
636 { "name": "gmail.com", "mode": "force-https", "pins": "google", "snionly": t rue }, 637 { "name": "gmail.com", "mode": "force-https", "pins": "google", "snionly": t rue },
637 { "name": "googlemail.com", "mode": "force-https", "pins": "google", "snionl y": true }, 638 { "name": "googlemail.com", "mode": "force-https", "pins": "google", "snionl y": true },
638 { "name": "www.gmail.com", "mode": "force-https", "pins": "google", "snionly ": true }, 639 { "name": "www.gmail.com", "mode": "force-https", "pins": "google", "snionly ": true },
639 { "name": "www.googlemail.com", "mode": "force-https", "pins": "google", "sn ionly": true }, 640 { "name": "www.googlemail.com", "mode": "force-https", "pins": "google", "sn ionly": true },
640 { "name": "google-analytics.com", "include_subdomains": true, "pins": "googl e", "snionly": true }, 641 { "name": "google-analytics.com", "include_subdomains": true, "pins": "googl e", "snionly": true },
641 { "name": "googlegroups.com", "include_subdomains": true, "pins": "google", "snionly": true } 642 { "name": "googlegroups.com", "include_subdomains": true, "pins": "google", "snionly": true }
642 ] 643 ]
643 } 644 }
OLDNEW
« no previous file with comments | « net/http/transport_security_state_static.h ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698