Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(58)

Issue 2369193002: [Remoting Host] Select Latest Valid Cert (Closed)

Created:
4 years, 2 months ago by Yuwei
Modified:
4 years, 2 months ago
CC:
chromium-reviews, chromoting-reviews_chromium.org
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

[Remoting Host] Select Latest Valid Cert Currently TokenValidatorBase will always select the first certificate for third-party authentication that matches the issuer but sometimes an incorrect certificate will be selected. This CL tries to improve this by: * Not selecting certificate that is obviously expired (now > valid_expiry). * Selecting the certificate with latest |valid_start| time. * Selecting the certifiacte with latest |valid_expiry| time when |valid_start| is the same. BUG=646944 Committed: https://crrev.com/e4807badb80cef2a24ffd3fdb3b8c28859c65a5c Cr-Commit-Position: refs/heads/master@{#422001}

Patch Set 1 #

Patch Set 2 : Add condition for null valid_expiry #

Patch Set 3 : Refactor comparison into function #

Total comments: 12

Patch Set 4 : Reviewer's Feedback #

Total comments: 1

Patch Set 5 : Add unittest #

Patch Set 6 : Fix comment #

Total comments: 2

Patch Set 7 : Reviewer's Feedback #

Patch Set 8 : Fix comments #

Patch Set 9 : Remove the [valid_start, inf) case #

Unified diffs Side-by-side diffs Delta from patch set Stats (+216 lines, -10 lines) Patch
M remoting/host/BUILD.gn View 1 2 3 4 5 6 7 8 1 chunk +1 line, -0 lines 0 comments Download
M remoting/host/token_validator_base.h View 1 2 3 4 1 chunk +2 lines, -0 lines 0 comments Download
M remoting/host/token_validator_base.cc View 1 2 3 4 5 6 7 8 2 chunks +59 lines, -10 lines 0 comments Download
A remoting/host/token_validator_base_unittest.cc View 1 2 3 4 1 chunk +154 lines, -0 lines 0 comments Download

Messages

Total messages: 25 (14 generated)
Yuwei
PTAL This should theoretically work but I still couldn't figure out how to do a ...
4 years, 2 months ago (2016-09-27 00:09:37 UTC) #4
Lambros
https://codereview.chromium.org/2369193002/diff/60001/remoting/host/token_validator_base.cc File remoting/host/token_validator_base.cc (right): https://codereview.chromium.org/2369193002/diff/60001/remoting/host/token_validator_base.cc#newcode48 remoting/host/token_validator_base.cc:48: net::X509Certificate* GetBestCertificate(net::X509Certificate* c1, I wonder if this could be ...
4 years, 2 months ago (2016-09-27 00:23:33 UTC) #5
Sergey Ulanov
I don't think you really need to mock X509Certificate to test this logic. The test ...
4 years, 2 months ago (2016-09-27 00:40:06 UTC) #7
Yuwei
PTAL https://codereview.chromium.org/2369193002/diff/60001/remoting/host/token_validator_base.cc File remoting/host/token_validator_base.cc (right): https://codereview.chromium.org/2369193002/diff/60001/remoting/host/token_validator_base.cc#newcode46 remoting/host/token_validator_base.cc:46: // Returns the best certificate to use. The ...
4 years, 2 months ago (2016-09-27 21:37:42 UTC) #8
Lambros
lgtm, thanks! https://codereview.chromium.org/2369193002/diff/120001/remoting/host/token_validator_base.cc File remoting/host/token_validator_base.cc (right): https://codereview.chromium.org/2369193002/diff/120001/remoting/host/token_validator_base.cc#newcode79 remoting/host/token_validator_base.cc:79: if (!c2_valid) Optional: If this 'if' were ...
4 years, 2 months ago (2016-09-27 22:13:58 UTC) #9
Yuwei
@lambroslambrou thank you and @sergeyu PTAL :) https://codereview.chromium.org/2369193002/diff/120001/remoting/host/token_validator_base.cc File remoting/host/token_validator_base.cc (right): https://codereview.chromium.org/2369193002/diff/120001/remoting/host/token_validator_base.cc#newcode79 remoting/host/token_validator_base.cc:79: if (!c2_valid) ...
4 years, 2 months ago (2016-09-27 22:22:50 UTC) #12
Sergey Ulanov
lgtm
4 years, 2 months ago (2016-09-29 18:20:28 UTC) #13
Yuwei
Thanks! BTW I just got a reply from Wan-Teh: ``` This definition shows |notAfter| is ...
4 years, 2 months ago (2016-09-29 18:43:26 UTC) #14
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2369193002/170001
4 years, 2 months ago (2016-09-30 00:51:09 UTC) #21
commit-bot: I haz the power
Committed patchset #9 (id:170001)
4 years, 2 months ago (2016-09-30 00:57:23 UTC) #23
commit-bot: I haz the power
4 years, 2 months ago (2016-09-30 01:01:22 UTC) #25
Message was sent while issue was closed.
Patchset 9 (id:??) landed as
https://crrev.com/e4807badb80cef2a24ffd3fdb3b8c28859c65a5c
Cr-Commit-Position: refs/heads/master@{#422001}

Powered by Google App Engine
This is Rietveld 408576698