Chromium Code Reviews
DescriptionRemove the "not_after" validation of policy timestamps
This CL disables the validation of policy timestamps against the current
device clocks, which was previously there to prevent loading policies
"from the future".
The disabled validation was originally intended as a protection against
a potential bug on DMServer side if it started sending wrongly big
timestamps. This could be a problem in theory, as after such a bug
occurs on the server side and is fixed then, the clients will refuse the
subsequent policy updates due to the protection on the client side
against policy rollbacks.
However, the decision now is made that this validation brings more
drawbacks than benefits as the device's clocks are quite often wrong.
BUG=701045
Review-Url: https://codereview.chromium.org/2820063005
Cr-Commit-Position: refs/heads/master@{#465964}
Committed: https://chromium.googlesource.com/chromium/src/+/5a159859f7164e629c68d8212db34a711fc5245d
Patch Set 1 #Patch Set 2 : Fix test #
Total comments: 12
Patch Set 3 : Review feedback #Patch Set 4 : Rebase #Messages
Total messages: 31 (24 generated)
|