Index: net/cert/cert_status_flags_list.h |
diff --git a/net/cert/cert_status_flags_list.h b/net/cert/cert_status_flags_list.h |
index 516631387d2db9968560c54d2aae155aaa39bc43..b2bcd319576294f45d9d161d461c5d9cf613c8b2 100644 |
--- a/net/cert/cert_status_flags_list.h |
+++ b/net/cert/cert_status_flags_list.h |
@@ -24,6 +24,9 @@ CERT_STATUS_FLAG(WEAK_KEY, 1 << 11) |
// 1 << 12 was used for CERT_STATUS_WEAK_DH_KEY |
CERT_STATUS_FLAG(PINNED_KEY_MISSING, 1 << 13) |
CERT_STATUS_FLAG(NAME_CONSTRAINT_VIOLATION, 1 << 14) |
+// Deprecated means "Valid beyond the deprecation period" (e.g. SHA-1 in 2017) |
davidben
2014/09/26 20:09:24
This comment is off. The flag is actually set for
|
+// If used after the deprecation period, it becomes WEAK_SIGNATURE_ALGORITHM |
+CERT_STATUS_FLAG(DEPRECATED_SIGNATURE_ALGORITHM, 1 << 15) |
// Bits 16 to 31 are for non-error statuses. |
CERT_STATUS_FLAG(IS_EV, 1 << 16) |