security/certverifier/CertVerifier.cpp
5e5b76d866341d47db93066b393af616b1e78f43
created 2016-01-29 10:15 -0800
pushed 2016-01-29 21:12 +0000
Wes Kocher Wes Kocher - Backed out changeset 7ec471c99263 (bug 1219482) to hopefully fix the intermittent hazard failures CLOSED TREE
7ec471c9926360990ad4ec55376c53b54638da3f
created 2016-01-28 10:36 -0500
pushed 2016-01-29 10:46 +0000
sajitk sajitk - Bug 1219482 - Replace PRLogModuleInfo with LazyLogModule in security subdirectory. r=froydnj
bb6bfd172d6e40b5d6a87d8118faf860c02f8545
created 2016-01-13 12:50 -0800
pushed 2016-01-21 10:51 +0000
David Keeler David Keeler - bug 1239455 - rework telemetry for SHA-1 certificates to reflect possible policy states r=Cykesiopka,mgoodwin,rbarnes
801655542a1297462d83ee52f4f96c809e69458d
created 2015-11-13 16:49 +0000
pushed 2015-11-14 21:22 +0000
Mark Goodwin Mark Goodwin - Bug 901698 - Implement OCSP-must-staple; r=keeler
0516d4db29a9d76361dd51331036e0b059b4dd60
created 2015-09-11 14:52 -0400
pushed 2015-09-13 18:58 +0000
Richard Barnes Richard Barnes - Bug 942515 - Show Untrusted Connection Error for SHA-1-based SSL certificates with notBefore >= 2016-01-01 r=keeler
fc86e9f2d6ea34b486058211fe468f4ada67f144
created 2015-08-21 15:14 +0100
pushed 2015-08-23 21:18 +0000
Mark Goodwin Mark Goodwin - Bug 1153444 - Fix up Key Pinning Telemetry (r=keeler)
31d0ae4d8c62e08a17784a6be2ad185d6b2f4e23
created 2015-07-09 07:22 +0100
pushed 2015-07-09 15:56 +0000
Mark Goodwin Mark Goodwin - Bug 1159155 - Add telemetry probe for SHA-1 usage (r=keeler)
a2b818a26d8528a8da37b16622e06df4d0c1676f
created 2015-06-29 22:19 +0200
pushed 2015-06-30 23:40 +0000
Cykesiopka Cykesiopka - Bug 1145679 - Reject EV status for end-entity EV certs with overly long validity periods. r=keeler
7da175eb7a6fc3673ce9a5fdee8b12fef1350fca
created 2015-06-01 13:55 -0700
pushed 2015-06-10 13:18 +0000
David Keeler David Keeler - bug 1170303 - treat malformed name information in certificates as a domain name mismatch r=Cykesiopka
4bc3d8e62192ea5ff9084681778e5e95648cfa48
created 2015-05-28 13:29 -0700
pushed 2015-06-10 01:59 +0000
Richard Barnes Richard Barnes - Bug 1010068 - Disable OCSP for DV certificates in Firefox for Android r=keeler
3ba889bb0741884c66bbe902a571ac2e1e2be8cd
created 2015-06-08 11:37 -0400
pushed 2015-06-09 16:52 +0000
Ryan VanderMeulen Ryan VanderMeulen - Backed out changeset fda85020d842 (bug 1010068) for Android test_cert_overrides.js failures.
fda85020d8424532ec552b7178b457015ca3d031
created 2015-05-28 13:29 -0700
pushed 2015-06-09 16:52 +0000
Richard Barnes Richard Barnes - Bug 1010068 - Disable OCSP for DV certificates in Firefox for Android r=keeler
f52c18aac7ce0949190da943ec5d4ee86627d0f8
created 2015-06-03 15:25 -0700
pushed 2015-06-04 12:39 +0000
Eric Rahm Eric Rahm - Bug 1165515 - Part 13-2: Replace usage of PRLogModuleLevel and PR_LOG_*. rs=froydnj
3c8ed81098ddbe4a4c09e7aa652b5288dc4ce0d3
created 2015-06-02 13:05 +0200
pushed 2015-06-03 01:20 +0000
Carsten "Tomcat" Book Carsten "Tomcat" Book - Backed out 14 changesets (bug 1165515) for linux x64 e10s m2 test failures
7c3b45a47811b55f4e973d996dd149c5d575721b
created 2015-06-01 22:17 -0700
pushed 2015-06-03 01:20 +0000
Eric Rahm Eric Rahm - Bug 1165515 - Part 13-2: Replace usage of PRLogModuleLevel and PR_LOG_*. rs=froydnj
3f1f9238e02fe107701bf3ab4237c0cb3b125710
created 2015-06-01 17:57 -0700
pushed 2015-06-02 11:11 +0000
Wes Kocher Wes Kocher - Backed out 14 changesets (bug 1165515) for b2g mochitest-6 permafail CLOSED TREE
150606c022a29517f43ee6907075170db825c947
created 2015-06-01 14:31 -0700
pushed 2015-06-02 11:11 +0000
Eric Rahm Eric Rahm - Bug 1165515 - Part 13-2: Replace usage of PRLogModuleLevel and PR_LOG_*. rs=froydnj
8a03e892db51e07a20a85f97abe073cee7be0fa0
created 2015-05-21 13:22 -0700
pushed 2015-05-22 18:02 +0000
Eric Rahm Eric Rahm - Bug 1165515 - Part 1: Convert PR_LOG to MOZ_LOG. r=froydnj
1853f12d7d8c336d0689a8d3e0e21e174609f50a
created 2015-04-06 16:10 -0700
pushed 2015-05-15 15:40 +0000
David Keeler David Keeler - bug 1141189 - implement skipping expensive revocation checks (OCSP fetching) for short-lived certificates r=rbarnes
b46612a5525552a32c511d9b223e1e8291262a13
created 2015-05-07 11:06 -0700
pushed 2015-05-12 23:24 +0000
David Keeler David Keeler - bug 1102436 - remove PublicKeyPinningService::CheckChainAgainstAllNames r=Cykesiopka
3cdce28ffcc6de50fac4fce22a8bca0a467db44b
created 2015-05-08 14:36 -0700
pushed 2015-05-09 21:17 +0000
Eric Rahm Eric Rahm - Bug 1162691 - Part 1: Remove instances of #ifdef PR_LOGGING in security. r=froydnj
98059179549d4e550a0593d5af1977d43160e743
created 2015-03-25 11:04 -0700
pushed 2015-04-17 19:45 +0000
David Keeler David Keeler - bug 1147497 - Add API for querying site pin status. Disallow overrides for sites that have pins. r=mmc r=smaug r=cykesiopka r=past
eee856befda3b54b11383be5192ce333de40ea08
created 2015-03-05 16:41 +0100
pushed 2015-03-06 21:23 +0000
Cykesiopka Cykesiopka - Bug 1139177 - RSA public key size checking cleanups. r=keeler
c6f3b60f6f8ab6a9c1d1918373968433d4e5e50b
created 2015-02-24 15:48 -0800
pushed 2015-02-27 18:20 +0000
David Keeler David Keeler - bug 1049740 - implement telemetry to measure compatibility impact of 2048-bit-minimum RSA keys r=briansmith
fa67b437a89ab8590a5bcd3a91a4d779f716c6dd
created 2015-01-23 06:17 +0100
pushed 2015-02-05 13:47 +0000
TheKK TheKK - Bug 1092398 - "remove unused CertVerifier enums (missing_cert_download_config and crl_download_config)". r=honzab.moz
f1ba8432414daea5876b80dce3a2e633c8434414
created 2014-12-17 21:31 -0500
pushed 2014-12-26 19:40 +0000
Kaspar Brand Kaspar Brand - Bug 1112487 - The signing certificates with key usage only non-repudiation is taken as invalid for signing. r=keeler
610eb25d2d63d18d7233d21aaf464471545ccab0
created 2014-12-11 23:22 -0800
pushed 2014-12-15 18:52 +0000
Brian Smith Brian Smith - Bug 1107666: Fix OCSP stapling telemetry (SSL_OCSP_STAPLING), r=keeler
c7c48ab6ee5e3e0c65e35966511e838bc680a80f
created 2014-10-28 15:28 -0700
pushed 2014-10-31 20:14 +0000
Brian Smith Brian Smith - Reland Bug 1063281, Part 9: Switch Gecko from NSS to CheckCertHostname, r=keeler
ed2cdcdb52408e549b5f5d47c6ebc02d506d83bb
created 2014-10-28 12:30 -0700
pushed 2014-10-29 01:53 +0000
Brian Smith Brian Smith - Back out cset 9b72d139e817 (Bug 1063281, Part 9) due to compatibility regressions on a CLOSED TREE, a=ryanvm
9b72d139e81766bdcf363c7b9ed0bf3f248c32d2
created 2014-09-21 17:43 -0700
pushed 2014-10-24 13:48 +0000
Brian Smith Brian Smith - Bug 1063281, Part 9: Switch Gecko from NSS to CheckCertHostname, r=keeler
f564fff0642cfbd82f7192d7e2d8b00610e16091
created 2014-10-18 15:18 +0200
pushed 2014-10-20 12:40 +0000
Cykesiopka Cykesiopka - Bug 622859 - Reject EV certificates with key sizes below RSA 2048. r=briansmith
209ec35a59c13bfccd4b5a787268cb4e1eaf1bb3
created 2014-10-17 13:14 +0200
pushed 2014-10-20 12:40 +0000
Carsten "Tomcat" Book Carsten "Tomcat" Book - Backed out changeset 3afdc3253979 (bug 622859) for breaking m1 tests
3afdc3253979b356a146c55e49eb68eb48580927
created 2014-10-16 05:13 +0200
pushed 2014-10-20 12:40 +0000
Cykesiopka Cykesiopka - Bug 622859 - Reject EV certificates with key sizes below RSA 2048. r=briansmith
4f90b7fb1918462222c557100342cdd627e2f3f3
created 2014-09-25 11:18 -0700
pushed 2014-09-26 20:54 +0000
David Keeler David Keeler - bug 1071308 - (2/2) remove libpkix-style chain validation callback from CertVerifier r=cviecco
9dc5491eb546b9d334fd305488d50891e2749773
created 2014-09-25 11:08 -0700
pushed 2014-09-26 20:54 +0000
David Keeler David Keeler - bug 1071308 - (1/2) rename pinning_enforcement_level to PinningMode for brevity r=cviecco
d02e70f0bf3d2f6028541d2a7c455266bc9597cd
created 2014-09-12 13:20 -0700
pushed 2014-09-17 00:06 +0000
David Keeler David Keeler - bug 1066190 - ensure that pinning checks are done for otherwise overridable errors r=mmc
c4d1c00413479524bbd1f9ef4ba1f0809099af65
created 2014-08-21 10:37 -0700
pushed 2014-08-22 01:22 +0000
David Keeler David Keeler - bug 1049095 - re-verify joinee certificate with joining hostname when joining connections r=briansmith r=mcmanus r=cviecco r=mmc r=rbarnes
68499003df5ed29ba5cc594aeac3b166f4730de7
created 2014-08-14 09:38 -0700
pushed 2014-08-14 20:21 +0000
David Keeler David Keeler - bug 1030963 - remove non-standard window.crypto functions/properties r=jst r=briansmith r=glandium
a4a8b3b58191206f53748d823cf255fba4042253
created 2014-08-02 08:49 -0700
pushed 2014-08-04 20:14 +0000
Brian Smith Brian Smith - Bug 1043041: Use mozilla::pkix::Time instead of PRTime, r=keeler
c989be71f8443b628a15cd0aab16f47de73d3582
created 2014-07-31 12:17 -0700
pushed 2014-08-01 15:52 +0000
Brian Smith Brian Smith - Bug 1041186, Part 2: Rename Input to Reader and InputBuffer to Input, r=keeler
c04d170a0bd9ad169065d5546a1149554a543422
created 2014-07-18 22:30 -0700
pushed 2014-08-01 15:52 +0000
Brian Smith Brian Smith - Bug 1041186, Part 1: Improve buffer overflow protection in mozilla::pkix, r=keeler
5f7dc391e8611d1f12f77d55f2c5a56ef8f6f29e
created 2014-07-18 11:48 -0700
pushed 2014-08-01 15:52 +0000
Brian Smith Brian Smith - Bug 1039064: Use strongly-typed enum instead of NSPR-style error handling, r=keeler
a6389627c3a4d841462b60223357bedc5494ebca
created 2014-07-14 16:43 -0700
pushed 2014-07-15 12:59 +0000
Brian Smith Brian Smith - Bug 1038098: Save intermediate certificates during TLS handshake, r=keeler
0ed88d692f42f34802beafcea77797f61c918155
created 2014-07-06 15:55 -0700
pushed 2014-07-10 12:47 +0000
Brian Smith Brian Smith - Bug 1035009: Stop using CERTCertList in mozilla::pkix, r=keeler
911d02f2c02a13fbdf80083f6d00886e35523f20
created 2014-07-03 16:59 -0700
pushed 2014-07-08 12:41 +0000
Brian Smith Brian Smith - Bug 1029247, Part 2: Parse certificates using mozilla::pkix::der, r=keeler
5d696c6fe0a7d44afa8955d08fc0e7dc1d80cb3c
created 2014-07-06 19:15 -0700
pushed 2014-07-08 12:41 +0000
Brian Smith Brian Smith - Bug 1035034: Fix typo in CertVerifier, r=cviecco
b3ebf7675c7bd1d85ed1b7290e1d2c3ae28a0490
created 2014-06-16 23:13 -0700
pushed 2014-06-23 14:42 +0000
Brian Smith Brian Smith - Bug 975229: Remove NSS-based certificate verification, r=keeler
2572716c3646aa70b0109e602ee5113c6ad17138
created 2014-06-19 00:13 -0700
pushed 2014-06-20 16:42 +0000
Brian Smith Brian Smith - Bug 1006812: Use mozilla::pkix::der to decode the key usage extension, r=keeler
bd1a3bb1b916fb44bb17339c6305fea4f02a6d35
created 2014-06-16 23:37 -0700
pushed 2014-06-19 14:39 +0000
Brian Smith Brian Smith - Bug 1026371: Remove useless comments in CertVerifier.cpp, r=cviecco
6dcd584751cc23bea5b56dc3c455640dd1aa8c6c
created 2014-05-28 15:28 -0700
pushed 2014-05-30 00:35 +0000
David Keeler David Keeler - bug 1006710 - add class of PSM errors to SEC and SSL errors r=briansmith
c288e2c355abaa840d36f1b754708bb466df767f
created 2014-05-21 15:42 -0700
pushed 2014-05-29 06:33 +0000
Camilo Viecco Camilo Viecco - Bug 1005142 - Part 1/2 - Add OCSP get capabilities to OCSPRequestor. r=keeler
776e1fd3824fd0a809c4b60f082faf955677e88d
created 2014-05-19 13:24 -0700
pushed 2014-05-20 13:27 +0000
Monica Chew Monica Chew - Bug 1011269: Forgot to qref to pick up keeler's changes (r=keeler)
1f5b5d9cbf72d570fb8e054713060243e44c303b
created 2014-05-19 13:04 -0700
pushed 2014-05-20 13:27 +0000
Monica Chew Monica Chew - Bug 1011269: Add CertVerifier::pinningEnforceTestMode (r=keeler)
a4ae7060f43ac1a4e49b30dfd7a95c5212940d4b
created 2014-05-15 18:59 -0700
pushed 2014-05-16 18:53 +0000
Brian Smith Brian Smith - Bug 1006958: Use mozilla::pkix::der to parse certificate policies instead of NSS, r=keeler
b9eff37173e1219027e2b5cb6822cb33504106b6
created 2014-05-14 01:02 -0700
pushed 2014-05-16 18:53 +0000
Brian Smith Brian Smith - Bug 1006041: Use mozilla::pkix::der for decoding the extended key usage extension, r=keeler
c968e47ef70893902ed49f65ade8a2ffe116ea11
created 2014-04-25 16:29 -0700
pushed 2014-05-02 12:30 +0000
Brian Smith Brian Smith - Bug 1002933: Use Strongly-typed enums more often in mozilla::pkix, r=mmc
affd460bc3d7ee6d8a6347bd7ae7faa4c7dc1ecd
created 2014-02-05 14:49 -0800
pushed 2014-05-01 14:50 +0000
Camilo Viecco Camilo Viecco - Bug 744204 - Allow Certificate key pinning Part 2 - Certverifier Interface. r=keeler
311bb33950fdce6caa552dbfe4915734920c91a2
created 2014-03-28 10:21 -0700
pushed 2014-04-03 01:56 +0000
Camilo Viecco Camilo Viecco - Bug 987816 - Part 1/3. Allow verifying with certificateUsageVerifyCA. r=dkeeler
dd433d12561bb75b984fe56734bcc67b3d8c6c07
created 2014-03-28 16:57 -0700
pushed 2014-03-29 16:01 +0000
Wes Kocher Wes Kocher - Backed out 2 changesets (bug 987816) for xpcshell orange
245d0cb5a7b32e10fdbd1cbcb42ca7380c2bfbce
created 2014-03-28 10:21 -0700
pushed 2014-03-29 16:01 +0000
Camilo Viecco Camilo Viecco - Bug 987816 - certificateUsageVerifyCA is OK verifcation option. r=dkeeler
less more (0) -60 tip