Chromium Code Reviews
DescriptionTurn off Expect-Staple reporting for private roots
Previously, Expect-Staple reports were sent for certificates chaining to
private roots, but with the certificate chains stripped out. However,
these reports are mostly just noise for site owners; they tend to
indicate that a MITM proxy did not provide an OCSP response, which is to
be expected. Moreover, these reports are not useful for answering the
interesting question about MITM proxies, which is whether they blindly
copy Must-Staple extensions (issue 633732). Thus, this CL disables
Expect-Staple reporting for private roots.
BUG=656227
Committed: https://crrev.com/53e947a174c199d639065dea59b736b30fb3bf08
Cr-Commit-Position: refs/heads/master@{#425866}
Patch Set 1 #Patch Set 2 : test fixes #
Messages
Total messages: 13 (8 generated)
|
|||||||||||||||||||||||||||||||||||||