Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(261)

Issue 2560343002: Disable SHA-1 for Enterprise Certs (Closed)

Created:
4 years ago by Ryan Sleevi
Modified:
4 years ago
Reviewers:
eroman, mattm
CC:
chromium-reviews, cbentzel+watch_chromium.org, eroman
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Disable SHA-1 for Enterprise Certs Disable SHA-1 unless CertVerifier::VERIFY_ENABLE_SHA1_LOCAL_ANCHORS is set. This flag is set based on the EnableSha1ForLocalAnchors policy for Chrome users. BUG=673036 Committed: https://crrev.com/d3d4039a2c95869ba38aa69b6bb542362e5f4574 Cr-Commit-Position: refs/heads/master@{#438399}

Patch Set 1 #

Patch Set 2 : Update net.gypi #

Total comments: 9

Patch Set 3 : Fix enterprise #

Patch Set 4 : Retweaked #

Unified diffs Side-by-side diffs Delta from patch set Stats (+511 lines, -122 lines) Patch
M net/cert/cert_verify_proc.cc View 1 2 3 1 chunk +21 lines, -23 lines 0 comments Download
M net/cert/cert_verify_proc_unittest.cc View 1 2 6 chunks +22 lines, -26 lines 0 comments Download
M net/data/ssl/certificates/README View 3 chunks +11 lines, -5 lines 0 comments Download
M net/data/ssl/certificates/crlset_by_intermediate_serial.raw View Binary file 0 comments Download
A net/data/ssl/certificates/intermediate_ca_cert.pem View 1 chunk +104 lines, -0 lines 0 comments Download
A net/data/ssl/certificates/ok_cert_by_intermediate.pem View 1 chunk +112 lines, -0 lines 0 comments Download
M net/data/ssl/certificates/x509_verify_results.chain.pem View 1 chunk +169 lines, -41 lines 0 comments Download
M net/data/ssl/scripts/ca.cnf View 1 chunk +1 line, -0 lines 0 comments Download
M net/data/ssl/scripts/generate-test-certs.sh View 28 chunks +66 lines, -27 lines 0 comments Download
M net/net.gypi View 1 4 chunks +5 lines, -0 lines 0 comments Download

Messages

Total messages: 29 (16 generated)
Ryan Sleevi
Eric: Do you have time to take a look at this? I can always punt ...
4 years ago (2016-12-09 23:07:40 UTC) #2
Ryan Sleevi
Punting to Matt :)
4 years ago (2016-12-13 00:19:27 UTC) #6
eroman
Oh hmm, i didn't even notice this. Looking...
4 years ago (2016-12-13 00:46:38 UTC) #8
mattm
lgtm
4 years ago (2016-12-13 01:17:17 UTC) #9
eroman
https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc File net/cert/cert_verify_proc.cc (right): https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc#newcode482 net/cert/cert_verify_proc.cc:482: // disabled on this date, but enterprises need more ...
4 years ago (2016-12-13 01:22:47 UTC) #12
Ryan Sleevi
Just trying to understand more to figure out what can be done to clarity here, ...
4 years ago (2016-12-13 01:29:57 UTC) #13
eroman
https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc File net/cert/cert_verify_proc.cc (right): https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc#newcode490 net/cert/cert_verify_proc.cc:490: // - ... unless it's in the intermediate and ...
4 years ago (2016-12-13 01:49:33 UTC) #14
Ryan Sleevi
https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc File net/cert/cert_verify_proc.cc (right): https://codereview.chromium.org/2560343002/diff/20001/net/cert/cert_verify_proc.cc#newcode492 net/cert/cert_verify_proc.cc:492: (!sha1_legacy_mode_enabled && On 2016/12/13 01:49:33, eroman (slow) wrote: > ...
4 years ago (2016-12-13 02:22:47 UTC) #15
Ryan Sleevi
Eric: Curious for your thoughts with the latest patch. Does that strike the balance in ...
4 years ago (2016-12-14 00:03:38 UTC) #20
eroman
LGTM Yes thanks, that is more readable to me.
4 years ago (2016-12-14 01:15:37 UTC) #21
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2560343002/60001
4 years ago (2016-12-14 01:35:35 UTC) #24
commit-bot: I haz the power
Committed patchset #4 (id:60001)
4 years ago (2016-12-14 02:40:39 UTC) #27
commit-bot: I haz the power
4 years ago (2016-12-14 02:44:39 UTC) #29
Message was sent while issue was closed.
Patchset 4 (id:??) landed as
https://crrev.com/d3d4039a2c95869ba38aa69b6bb542362e5f4574
Cr-Commit-Position: refs/heads/master@{#438399}

Powered by Google App Engine
This is Rietveld 408576698