Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(208)

Issue 2920013003: Add policies support to VerifyCertificateChain(). (Closed)

Created:
3 years, 6 months ago by eroman
Modified:
3 years, 6 months ago
Reviewers:
mattm
CC:
chromium-reviews, cbentzel+watch_chromium.org, net-reviews_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Add policies support to VerifyCertificateChain(). Support is compliant with RFC 5280 and supports all the policy extensions specified therein: * Inhibit Any Policy * Policy Constraints * Policies * Policy Mappings Testing is done solely using the PKITS test suite, which has fairly good coverage of these extensions: 4.8 (Certificate Policies) 4.9 (Require Explicit Policy) 4.10 (Policy Mappings) 4.11 (Inhibit Policy Mapping) 4.12 (Inhibit Any Policy) This is a re-land of: https://codereview.chromium.org/2903283002 BUG=634456, 634453, 634452 Review-Url: https://codereview.chromium.org/2920013003 Cr-Commit-Position: refs/heads/master@{#476773} Committed: https://chromium.googlesource.com/chromium/src/+/0507e9f17c57e79a10f61eee6c815368977ade54

Patch Set 1 : Original patch #

Patch Set 2 : Fix assertion on linux debug builds #

Unified diffs Side-by-side diffs Delta from patch set Stats (+941 lines, -190 lines) Patch
M net/cert/internal/nist_pkits_unittest.h View 1 chunk +5 lines, -3 lines 0 comments Download
M net/cert/internal/nist_pkits_unittest.cc View 1 chunk +6 lines, -3 lines 0 comments Download
M net/cert/internal/path_builder.cc View 1 chunk +6 lines, -3 lines 0 comments Download
M net/cert/internal/test_helpers.h View 1 chunk +10 lines, -0 lines 0 comments Download
M net/cert/internal/test_helpers.cc View 1 chunk +2 lines, -1 line 0 comments Download
M net/cert/internal/verify_certificate_chain.h View 3 chunks +136 lines, -41 lines 0 comments Download
M net/cert/internal/verify_certificate_chain.cc View 1 20 chunks +732 lines, -128 lines 0 comments Download
M net/cert/internal/verify_certificate_chain_pkits_unittest.cc View 3 chunks +25 lines, -7 lines 0 comments Download
M net/cert/internal/verify_certificate_chain_unittest.cc View 1 chunk +7 lines, -2 lines 0 comments Download
M net/third_party/nist-pkits/generate_tests.py View 2 chunks +11 lines, -2 lines 0 comments Download
M net/third_party/nist-pkits/pkits_testcases-inl.h View 1 chunk +1 line, -0 lines 0 comments Download

Messages

Total messages: 11 (7 generated)
eroman
This is a re-land of earlier CL (https://codereview.chromium.org/2903283002) The only change from the earlier version ...
3 years, 6 months ago (2017-06-02 18:53:09 UTC) #4
mattm
lgtm
3 years, 6 months ago (2017-06-02 19:23:57 UTC) #5
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2920013003/20001
3 years, 6 months ago (2017-06-02 19:41:18 UTC) #8
commit-bot: I haz the power
3 years, 6 months ago (2017-06-02 20:39:36 UTC) #11
Message was sent while issue was closed.
Committed patchset #2 (id:20001) as
https://chromium.googlesource.com/chromium/src/+/0507e9f17c57e79a10f61eee6c81...

Powered by Google App Engine
This is Rietveld 408576698