Bug 1005364: Disable pinning for all mozilla properties (r=keeler)
--- a/security/manager/boot/src/StaticHPKPins.h
+++ b/security/manager/boot/src/StaticHPKPins.h
@@ -186,20 +186,15 @@ const StaticPinset kPinSet_mozilla_test
/*Domainlist*/
typedef struct {
const char *mHost;
const bool mIncludeSubdomains;
const StaticPinset *pinset;
} TransportSecurityPreload;
static const TransportSecurityPreload kPublicKeyPinningPreloadList[] = {
- { "addons.mozilla.net", true, &kPinSet_mozilla },
- { "addons.mozilla.org", true, &kPinSet_mozilla },
- { "cdn.mozilla.net", true, &kPinSet_mozilla_cdn },
- { "cdn.mozilla.org", true, &kPinSet_mozilla_cdn },
{ "exclude-subdomains.pinning.example.com", false, &kPinSet_mozilla_test },
{ "include-subdomains.pinning.example.com", true, &kPinSet_mozilla_test },
- { "media.mozilla.com", true, &kPinSet_mozilla_cdn },
};
-static const int kPublicKeyPinningPreloadListLength = 7;
+static const int kPublicKeyPinningPreloadListLength = 2;
-const PRTime kPreloadPKPinsExpirationTime = INT64_C(1409867186821000);
+const PRTime kPreloadPKPinsExpirationTime = INT64_C(1410109244157000);
--- a/security/manager/tools/PreloadedHPKPins.json
+++ b/security/manager/tools/PreloadedHPKPins.json
@@ -88,17 +88,18 @@
"name": "mozilla_test",
"static_spki_hashes": [
"End Entity Test Cert"
]
}
],
"entries": [
- { "name": "addons.mozilla.org", "include_subdomains": true, "pins": "mozilla" },
- { "name": "addons.mozilla.net", "include_subdomains": true, "pins": "mozilla" },
- { "name": "cdn.mozilla.net", "include_subdomains": true, "pins": "mozilla_cdn" },
- { "name": "cdn.mozilla.org", "include_subdomains": true, "pins": "mozilla_cdn" },
- { "name": "media.mozilla.com", "include_subdomains": true, "pins": "mozilla_cdn" },
+ // Disable until bug 1005653 is fixed.
+ // { "name": "addons.mozilla.org", "include_subdomains": true, "pins": "mozilla" },
+ // { "name": "addons.mozilla.net", "include_subdomains": true, "pins": "mozilla" },
+ // { "name": "cdn.mozilla.net", "include_subdomains": true, "pins": "mozilla_cdn" },
+ // { "name": "cdn.mozilla.org", "include_subdomains": true, "pins": "mozilla_cdn" },
+ // { "name": "media.mozilla.com", "include_subdomains": true, "pins": "mozilla_cdn" },
{ "name": "include-subdomains.pinning.example.com", "include_subdomains": true, "pins": "mozilla_test" },
{ "name": "exclude-subdomains.pinning.example.com", "include_subdomains": false, "pins": "mozilla_test" }
]
}