Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(2140)

Unified Diff: net/cert/cert_verify_proc_mac.cc

Issue 2735733003: Disable commonName matching for certificates (Closed)
Patch Set: Created 3 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « net/cert/cert_verify_proc_ios.cc ('k') | net/cert/cert_verify_proc_openssl.cc » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: net/cert/cert_verify_proc_mac.cc
diff --git a/net/cert/cert_verify_proc_mac.cc b/net/cert/cert_verify_proc_mac.cc
index 987eed236e46f14d2f9066ebd9a0ecc87c6d2a57..234d95997494cd86d831c4f408b429756515beab 100644
--- a/net/cert/cert_verify_proc_mac.cc
+++ b/net/cert/cert_verify_proc_mac.cc
@@ -988,8 +988,8 @@ int VerifyWithGivenFlags(X509Certificate* cert,
break;
}
- // Perform hostname verification independent of SecTrustEvaluate. In order to
- // do so, mask off any reported name errors first.
+ // Hostname validation is handled by CertVerifyProc, so mask off any errors
+ // that SecTrustEvaluate may have set, as its results are not used.
verify_result->cert_status &= ~CERT_STATUS_COMMON_NAME_INVALID;
// TODO(wtc): Suppress CERT_STATUS_NO_REVOCATION_MECHANISM for now to be
« no previous file with comments | « net/cert/cert_verify_proc_ios.cc ('k') | net/cert/cert_verify_proc_openssl.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698