Brian Smith
|
2bd47f2cb9
|
Bug 975229: Remove NSS-based certificate verification, r=keeler
--HG--
extra : rebase_source : 49cb20f1b51e2d9993a35decd820764e20ad9be9
|
2014-06-16 23:13:29 -07:00 |
|
Brian Smith
|
c214d0f55e
|
Bug 1026261: Remove CERTCertificate from mozilla::pkix revocation checking API, r=keeler
--HG--
extra : rebase_source : 6798f494bd351961ea02abba07b5860839bbc418
|
2014-06-20 10:10:51 -07:00 |
|
David Keeler
|
6dc7ca62d1
|
bug 997509 - heed expired Revoked or Unknown OCSP responses r=briansmith
|
2014-06-20 09:01:57 -07:00 |
|
Brian Smith
|
84f52d8461
|
Bug 1006812: Use mozilla::pkix::der to decode the key usage extension, r=keeler
--HG--
extra : rebase_source : e445c913994dc027e1179543d7b6cab2505e734d
|
2014-06-19 00:13:20 -07:00 |
|
Brian Smith
|
81e6beaa4b
|
Bug 1022970: Switch from UNIFIED_SOURCES back to SOURCES in security/pkix, security/certverifier, and security/manager/ssl/src, r=keeler
--HG--
extra : rebase_source : 7d45d018be6b23af199c1e9c858fb5bb3bb5a01b
|
2014-06-16 22:57:55 -07:00 |
|
Brian Smith
|
8db16ecca0
|
Bug 1026371 : Remove useless comments in CertVerifier.cpp, r=cviecco
--HG--
extra : rebase_source : 58444ab17c68bcde6938540b3b074af55e417687
|
2014-06-16 23:37:53 -07:00 |
|
David Keeler
|
c251954bfe
|
bug 1017826 - follow-up to fix indentation r=me a=whitespace-only DONTBUILD
|
2014-06-17 09:14:00 -07:00 |
|
Harsh Pathak
|
ca13d59d69
|
Bug 1017826 - prevent a potential memory leak in OCSPCache::Put. r=keeler
|
2014-06-16 20:27:00 +02:00 |
|
Brian Smith
|
f3ab0b43c6
|
Bug 1020683, Part 1: Remove internal uses of CERTCertificate from mozilla::pkix::VerifyEncodedOCSPResponse, r=keeler
--HG--
extra : rebase_source : 416938498080c4d44874025f1da4562ab1c7c3c8
|
2014-06-05 15:18:32 -07:00 |
|
David Keeler
|
cb6b2b4ade
|
bug 1019198 - fail handshake if given an expired OCSP response and fetching a new one fails r=briansmith
|
2014-06-06 09:20:50 -07:00 |
|
Brian Smith
|
c9249cca82
|
Bug 1019814: Remove CERTCertificate dependency from TrustDomain::GetCertTrust, r=keeler
--HG--
extra : rebase_source : 9abf0522f02d00ac2f63f2327ddbe8d119ffc64f
|
2014-06-03 10:47:25 -07:00 |
|
Camilo Viecco
|
fc11f7c21d
|
Bug 991815 - Part 1/2 - Allow intermediate OCSP responses up to 1 year old. r=keeler
--HG--
extra : rebase_source : 28d5336da1dc44932b92ce2c59fca5fcb2b8a3d8
|
2014-05-30 16:12:36 -07:00 |
|
Brian Smith
|
833425eae1
|
Bug 1010634, Part 6: Enable -Wall with a few exceptions for certverifier, r=cviecco
--HG--
extra : rebase_source : 611f0d65e7edb74345a4a599a6606de37e3da75e
|
2014-05-15 21:56:23 -07:00 |
|
Brian Smith
|
7a871c3cee
|
Bug 1010634, Part 3: Fix more warnings in CertVerifier, r=cviecco
--HG--
extra : rebase_source : 21e79fbc472aeccec7df213e0cd8d99bebfbff75
|
2014-05-29 20:17:53 -07:00 |
|
Cykesiopka
|
ea035ab7a4
|
Bug 917510 - Replace SHA-1 fingerprints of EV certs in ExtendedValidation.cpp with SHA-2 fingerprints. r=briansmith, r=kwilson
|
2014-05-30 00:01:00 -04:00 |
|
David Keeler
|
56379872a2
|
bug 1006710 - add class of PSM errors to SEC and SSL errors r=briansmith
|
2014-05-28 15:28:03 -07:00 |
|
Camilo Viecco
|
44bf536cc4
|
Bug 1005142 - Part 1/2 - Add OCSP get capabilities to OCSPRequestor. r=keeler
--HG--
extra : rebase_source : ee4a86bf02a466a31de8b0b6cd7ce375a7f28c6d
|
2014-05-21 15:42:21 -07:00 |
|
Camilo Viecco
|
1eac4f4b6c
|
Bug 1010594 - Part 1/2 OCSP url check - r=briansmith
--HG--
extra : rebase_source : 0b26339d33db90722401ae1d8ac255d0390aea30
|
2014-05-16 13:53:14 -07:00 |
|
Monica Chew
|
1d542c52b2
|
Bug 1011269: Forgot to qref to pick up keeler's changes (r=keeler)
|
2014-05-19 13:24:41 -07:00 |
|
Monica Chew
|
8bc2f051f9
|
Bug 1011269: Add CertVerifier::pinningEnforceTestMode (r=keeler)
|
2014-05-19 13:04:40 -07:00 |
|
Brian Smith
|
ed25ac818b
|
Bug 1010634, Part 1: Fix compiler warnings in certverifier, r=cviecco
--HG--
extra : rebase_source : f8d925f042040368b038b62bc1d0c9d4d6d04618
|
2014-05-14 17:46:32 -07:00 |
|
Brian Smith
|
b3711e99df
|
Bug 1006958: Use mozilla::pkix::der to parse certificate policies instead of NSS, r=keeler
--HG--
extra : rebase_source : fde88efebc1025bc4f825aa38df809d04b1b250a
|
2014-05-15 18:59:52 -07:00 |
|
Brian Smith
|
e1de62ff87
|
Bug 1006041: Use mozilla::pkix::der for decoding the extended key usage extension, r=keeler
--HG--
extra : rebase_source : b4b62f117d653784eb6ad058554faf520a1bd90b
|
2014-05-14 01:02:34 -07:00 |
|
Gervase Markham
|
4ce70c195e
|
Bug 1007195 - Change licensing on mozilla::pkix to dual Apache 2/MPL 2. r=briansmith.
|
2014-05-14 14:37:25 +01:00 |
|
David Keeler
|
6c916db011
|
bug 982248 - NSSCertDBTrustDomain: specify timeout for OCSP requests r=briansmith
|
2014-05-01 15:07:55 -07:00 |
|
Brian Smith
|
6b71be8400
|
Bug 1002933: Use Strongly-typed enums more often in mozilla::pkix, r=mmc
--HG--
extra : rebase_source : 3f67f48d1f4150df0830f89e6c07bbbf3a8fc7e8
|
2014-04-25 16:29:26 -07:00 |
|
Camilo Viecco
|
06f960a801
|
Bug 744204 - Allow Certificate key pinning Part 2 - Certverifier Interface. r=keeler
--HG--
extra : rebase_source : 2f9748ba0b241c697e22b7ff72f2f5a0fad4a2ca
|
2014-02-05 14:49:10 -08:00 |
|
David Keeler
|
2a77846f27
|
bug 977865 - mozilla::pkix: add backoff for ocsp fetching when a responder fails r=cviecco
|
2014-04-28 16:38:15 -07:00 |
|
Camilo Viecco
|
0905fe7590
|
Bug 987816 - Part 1/3. Allow verifying with certificateUsageVerifyCA. r=dkeeler
--HG--
extra : rebase_source : 7530839c9c02d56936e322f897de96d80a60a18f
|
2014-03-28 10:21:30 -07:00 |
|
Wes Kocher
|
51005ce03d
|
Backed out 2 changesets (bug 987816) for xpcshell orange
Backed out changeset 245d0cb5a7b3 (bug 987816)
Backed out changeset b714220dd39d (bug 987816)
|
2014-03-28 16:57:12 -07:00 |
|
Camilo Viecco
|
96a8f62c2d
|
Bug 987816 - certificateUsageVerifyCA is OK verifcation option. r=dkeeler
--HG--
extra : rebase_source : 0e000dc85705e1c61773e8fc73425fe80e0b9134
|
2014-03-28 10:21:30 -07:00 |
|
David Keeler
|
676eaf13b4
|
bug 985201 - rename insanity::pkix to mozilla::pkix r=cviecco r=briansmith
--HG--
rename : security/insanity/include/insanity/ScopedPtr.h => security/pkix/include/pkix/ScopedPtr.h
rename : security/insanity/include/insanity/bind.h => security/pkix/include/pkix/bind.h
rename : security/insanity/include/insanity/nullptr.h => security/pkix/include/pkix/nullptr.h
rename : security/insanity/include/insanity/pkix.h => security/pkix/include/pkix/pkix.h
rename : security/insanity/include/insanity/pkixtypes.h => security/pkix/include/pkix/pkixtypes.h
rename : security/insanity/lib/pkixbind.cpp => security/pkix/lib/pkixbind.cpp
rename : security/insanity/lib/pkixbuild.cpp => security/pkix/lib/pkixbuild.cpp
rename : security/insanity/lib/pkixcheck.cpp => security/pkix/lib/pkixcheck.cpp
rename : security/insanity/lib/pkixcheck.h => security/pkix/lib/pkixcheck.h
rename : security/insanity/lib/pkixder.cpp => security/pkix/lib/pkixder.cpp
rename : security/insanity/lib/pkixder.h => security/pkix/lib/pkixder.h
rename : security/insanity/lib/pkixkey.cpp => security/pkix/lib/pkixkey.cpp
rename : security/insanity/lib/pkixocsp.cpp => security/pkix/lib/pkixocsp.cpp
rename : security/insanity/lib/pkixutil.h => security/pkix/lib/pkixutil.h
rename : security/insanity/moz.build => security/pkix/moz.build
rename : security/insanity/test/lib/moz.build => security/pkix/test/lib/moz.build
rename : security/insanity/test/lib/pkixtestutil.cpp => security/pkix/test/lib/pkixtestutil.cpp
rename : security/insanity/test/lib/pkixtestutil.h => security/pkix/test/lib/pkixtestutil.h
|
2014-03-20 14:29:21 -07:00 |
|
David Keeler
|
609e9a9f16
|
bug 969048 - adjust OCSP stapling telemetry for insanity::pkix r=briansmith r=cviecco
|
2014-03-13 09:41:03 -07:00 |
|
David Keeler
|
8fc5d6daee
|
bug 915932 - cache OCSP responses when using insanity::pkix r=cviecco r=briansmith
|
2014-03-12 13:08:48 -07:00 |
|
David Keeler
|
341b865887
|
bug 982403 - separate the compilation of certverifier and insanity::pkix r=cviecco r=briansmith
--HG--
rename : security/certverifier/moz.build => security/insanity/moz.build
|
2014-03-12 13:08:18 -07:00 |
|
Camilo Viecco
|
dcc3cb858e
|
Bug 962740 - Batch of 3 CA Certs to be granted EV capabilites. r=keeler
|
2014-02-26 14:41:02 -08:00 |
|
David Keeler
|
6d6c54d69b
|
Bug 974715 - Create more flexible OCSP response generation code. r=briansmith, r=cviecco
|
2014-03-10 14:04:31 -07:00 |
|
Brian Smith
|
2f3b70ffb5
|
Bug 978528: Return the correct error message when no potential issuers are found during path bulding in insanitY::pkix, r=cviecco
--HG--
extra : rebase_source : 71f806312ad322bc2971e7efaea2da217b07efad
|
2014-03-01 20:55:51 -08:00 |
|
Brian Smith
|
c13108b590
|
Bug 921885: Use insanity::pkix for EV cert verification when insanity::pkix is the selected implementation, r=cviecco, r=keeler
--HG--
extra : rebase_source : b1fd1f8eace675484b3c2d568e5e74f767f1d2ad
|
2014-02-23 22:15:53 -08:00 |
|
Brian Smith
|
64ea6aa0a3
|
Bug 921886: Add certificate policiy support to insanity::pkix, r=keeler, r=cviecco
--HG--
extra : rebase_source : 6522e2c2f57f59fe23c0ed0c838f1f54236bdafc
|
2014-02-24 12:37:45 -08:00 |
|
Brian Smith
|
db4827dbd4
|
Bug 975122: Allow cert error overrides when insanity::pkix is used, r?cviecco, r?keeler
--HG--
extra : rebase_source : 47f5e779a16c462e40baa2d9cec2e83946c9076c
|
2014-02-22 19:08:06 -08:00 |
|
Brian Smith
|
144b29ee4c
|
Bug 915931, Part 3: Integrate insanity::pkix OCSP support, r=keeler, r=cviecco
--HG--
extra : rebase_source : 4b54682ca6d97e2ec7709b9a5c93ddea71126f8b
|
2014-02-16 17:35:40 -08:00 |
|
Brian Smith
|
8180cbf4d1
|
Bug 878932, Part 1: Add OCSP response parsing & validation to insanity::pkix, r=keeler
--HG--
extra : rebase_source : 23771eaf97f67e5feb69d50a0c96dd4da31ae964
extra : source : b0511882e4c94c0960ef8533b381e8d72706172e
|
2014-02-16 18:09:06 -08:00 |
|
Brian Smith
|
83e4eaa908
|
Bug 896620: Make marketplace certs work on in all products, r=keeler
--HG--
extra : source : 86ec7137a8892f75918c77e605df970f5b96ef62
extra : histedit_source : 33326790804d49e6ec658626116ebf870d94d445
|
2014-02-14 14:37:07 -08:00 |
|
Brian Smith
|
bbf60e0ee9
|
Bug 878932, Part 1: add insanity::pkix as an option for certificate verification, r=keeler, r=cviecco
--HG--
extra : rebase_source : c1f75dff6ac7f32e082517af701654abebaee250
|
2014-02-10 11:41:12 -08:00 |
|
Camilo Viecco
|
a59ac56b87
|
Bug 790809 - Add callback for in libpkix for extra app checks (in usage sslserver). r=dkeeler
|
2014-02-05 14:49:14 -08:00 |
|
Brian Smith
|
c27359c631
|
Bug 921891, part 3: Add basic building and verification, r=keeler, r=cviecco
--HG--
extra : rebase_source : 7b01773c47445efc40941ae251d03f505f429be6
extra : source : 2a36da04b931740858d51023b2cc8ef7528ef740
|
2014-02-02 21:21:00 -08:00 |
|
Daniel Holbert
|
9e611f121a
|
Bug 968323: Declare prlog variables inside #ifdef PR_LOGGING instead of MOZ_LOGGING, in /security, to fix build failures in --disable-logging builds. r=briansmith
|
2014-02-05 22:11:26 -08:00 |
|
Daniel Holbert
|
5473547676
|
Bug 968491: Mark security/certverifier/ as FAIL_ON_WARNINGS. r=briansmith
|
2014-02-05 22:11:24 -08:00 |
|
Camilo Viecco
|
6e842a83c4
|
Bug 968491 helper-patch: Temporarily #ifdef out static function 'insertErrorIntoVerifyLog' to address Wunused-function build warning. r=briansmith
|
2014-02-05 22:11:16 -08:00 |
|