Patrick McManus
|
889702b1cc
|
bug 1003448 - HTTP/2 Alternate Service and Opportunistic Security [1/2 PSM] r=keeler
|
2014-08-20 16:30:16 -04:00 |
|
Martin Thomson
|
0f65e8939d
|
Bug 1072382 - Remove version intolerance marker on inappropriate_fallback alert, r=keeler
|
2014-10-02 10:03:30 -07:00 |
|
Carsten "Tomcat" Book
|
3d0ce0976d
|
merge fx-team to mozilla-central a=merge
|
2014-09-30 15:10:47 +02:00 |
|
Cykesiopka
|
fe6534baab
|
Bug 1073865 - Add missing SSL_ERROR l10n strings v1. r=dkeeler
|
2014-09-27 14:02:00 +02:00 |
|
Camilo Viecco
|
7caba5f564
|
Bug 787133 - (hpkp) Part 2/2. Tests r=keeler
|
2014-09-29 20:31:08 -07:00 |
|
Stephen Pohl
|
d16e3504d5
|
Mac v2 signing - Bug 1060562 - Update xpcshell-tests for the new v2 bundle structure on OSX. r=jmaher
|
2014-09-29 11:51:29 -07:00 |
|
ffxbld
|
5b68b0e1b2
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-046 - a=hpkp-update
|
2014-09-27 03:16:58 -07:00 |
|
ffxbld
|
83cf7b8500
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-046 - a=hsts-update
|
2014-09-27 03:16:56 -07:00 |
|
David Keeler
|
3e19283352
|
bug 1071308 - (1/2) rename pinning_enforcement_level to PinningMode for brevity r=cviecco
|
2014-09-25 11:08:36 -07:00 |
|
Camilo Viecco
|
3353899ecd
|
Bug 787133 - (hpkp) Part 1/2. Header Parsing and interface within PSM. r=keeler, r=mcmanus
|
2014-09-03 10:24:12 -07:00 |
|
Richard Barnes
|
60c48eb89d
|
Bug 1045973 - sec_error_extension_value_invalid: mozilla::pkix does not accept certificates with x509v3 extensions in x509v1 or x509v2 certificates r=keeler
|
2014-09-23 16:48:54 -04:00 |
|
Ehsan Akhgari
|
17d927530c
|
Fix more bad implicit constructors in security, blanket-rs=bsmith, no bug
|
2014-09-23 09:13:26 -04:00 |
|
Vlatko Markovic
|
081fef0a34
|
Bug 1059216 - Verification of Trusted Hosted Apps manifest signature, part 1. r=dkeeler,rlb
|
2014-09-22 07:58:59 -07:00 |
|
Robin Thunell
|
3b04dbe2e6
|
Bug 1059208 - Add scripts for signing manifest files of Trusted Hosted Apps r=dkeeler
|
2014-09-22 07:58:59 -07:00 |
|
ffxbld
|
57fd0ff0d0
|
No bug, Automated HPKP preload list update from host b-linux64-ix-0007 - a=hpkp-update
|
2014-09-20 03:17:29 -07:00 |
|
ffxbld
|
db7a12fb67
|
No bug, Automated HSTS preload list update from host b-linux64-ix-0007 - a=hsts-update
|
2014-09-20 03:17:26 -07:00 |
|
Arthur Edelstein
|
758e11be76
|
Bug 967977 - Add pref to disable session identifiers (session tickets and session IDs). r=dkeeler
|
2014-09-08 15:32:00 -04:00 |
|
Patrick McManus
|
b73c2efb3c
|
bug 1003448 - HTTP/2 Alternate Service and Opportunistic Security [1/2 PSM] r=keeler
|
2014-08-20 16:30:16 -04:00 |
|
Martin Thomson
|
6106ddd104
|
Bug 1075991 - Tracking cause of inappropriate TLS version fallback, r=keeler
|
2014-10-03 11:01:24 -07:00 |
|
Martin Thomson
|
c8f2753778
|
Bug 1075991 - Remember version intolerance reason code, r=keeler
|
2014-10-03 11:01:24 -07:00 |
|
Monica Chew
|
4ec9c87796
|
Bug 1030135: Set is_moz if the pinset name contains mozilla, set bucket id for pinsets containing the string mozilla (r=keeler)
|
2014-10-02 16:45:13 -07:00 |
|
J.C. Jones
|
550cc2e2c1
|
Bug 1054498 - Report pinning violations by CA r=keeler
|
2014-10-17 10:33:50 -07:00 |
|
Carsten "Tomcat" Book
|
9679e704b6
|
Backed out changeset f5fa8ea86d3b (bug 622859)
|
2014-10-17 13:13:01 +02:00 |
|
Cykesiopka
|
da9e1d2029
|
Bug 622859 - Tests for bug 622859. r=briansmith,keeler
|
2014-10-16 05:22:00 +02:00 |
|
David Keeler
|
f76c788d8e
|
bug 1055238 - add nsNSSCertListFakeTransport so nsIX509CertList can survive the child process r=rbarnes
|
2014-09-16 15:49:37 -07:00 |
|
David Keeler
|
01f24cb277
|
bug 1055238 - clean up nsNSSCertificateFakeTransport.{cpp,h} for style nits r=rbarnes
|
2014-09-16 13:24:13 -07:00 |
|
Camilo Viecco
|
2cb42272c4
|
Bug 787133 - (hpkp) testing of internal storage and idl r=keeler.
--HG--
extra : rebase_source : c4f83f38a3b8f293a1ca61f2f0a6f90df6ff7840
|
2014-09-12 14:59:37 -07:00 |
|
Camilo Viecco
|
025a95d373
|
Bug 787133 - (hpkp) Internal storage of hpkp data. r=keeler.
--HG--
extra : rebase_source : 1ef88ab5ebcf9634bd1de76ec1c9543eb87d265b
|
2014-09-12 14:59:37 -07:00 |
|
David Keeler
|
bc48dc5b1b
|
bug 1066190 - ensure that pinning checks are done for otherwise overridable errors r=mmc
|
2014-09-12 13:20:43 -07:00 |
|
Camilo Viecco
|
6d0d3604e5
|
Bug 1067565 - Built-in pins expires decades later. r=keeler
|
2014-09-15 17:17:12 -07:00 |
|
Wes Kocher
|
42b3b1714c
|
Merge m-c to inbound a=merge
|
2014-09-15 16:41:45 -07:00 |
|
ffxbld
|
06f4c95ee9
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-318 - a=hpkp-update
|
2014-09-15 14:35:39 -07:00 |
|
ffxbld
|
2787427cf9
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-318 - a=hsts-update
|
2014-09-15 14:35:37 -07:00 |
|
David Keeler
|
69ebd139fa
|
bug 973048 - follow-up to add another missed #include r=bustage on a CLOSED TREE
|
2014-09-15 13:50:18 -07:00 |
|
David Keeler
|
feeba637e3
|
bug 973048 - follow-up to add #include for ScopedPtr r=bustage on a CLOSED TREE
|
2014-09-15 13:02:47 -07:00 |
|
David Keeler
|
07cc464c9e
|
bug 973048 - replace nsNSSCleaner with Scoped types r=rbarnes
|
2014-09-15 12:31:43 -07:00 |
|
Carsten "Tomcat" Book
|
6d0df443bf
|
merge m-i to m-c a=merge
|
2014-09-12 15:07:38 +02:00 |
|
ffxbld
|
36c33a0bd0
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-021 - a=hpkp-update
|
2014-09-11 20:51:37 -07:00 |
|
ffxbld
|
baa0da8253
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-021 - a=hsts-update
|
2014-09-11 20:51:35 -07:00 |
|
Giovanni Sferro
|
596d5c0c5c
|
Bug 1050518 - Remove nsICertificatePrincipal. r=keeler
|
2014-09-10 20:31:00 -04:00 |
|
Brian Smith
|
93dd638168
|
Bug 1063006: Centralize direct use of NSS for crypto in the mozilla::pkix test suite, r=keeler
--HG--
rename : security/pkix/test/lib/pkixtestutil.cpp => security/pkix/test/lib/pkixtestnss.cpp
extra : rebase_source : 93515d39abf91168fa86268f9b26f8c62d0d411e
|
2014-08-31 17:47:09 -07:00 |
|
Ehsan Akhgari
|
8f1ca2a08f
|
Bug 1064356 - Fix more bad implicit constructors in security; r=bsmith
|
2014-09-08 20:47:36 -04:00 |
|
David Keeler
|
e59d626477
|
bug 1004781 - follow-up to add "DigiCert ECC Secure Server CA" to Facebook's pinset r=mmc
|
2014-09-08 09:33:03 -07:00 |
|
Carsten "Tomcat" Book
|
ef8e5b7042
|
merge mozilla-inbound to mozilla-central a=merge
|
2014-09-08 15:22:16 +02:00 |
|
ffxbld
|
c132f161fe
|
No bug, Automated HPKP preload list update from host b-linux64-ix-0009 - a=hpkp-update
|
2014-09-06 03:17:54 -07:00 |
|
ffxbld
|
982f13ce9d
|
No bug, Automated HSTS preload list update from host b-linux64-ix-0009 - a=hsts-update
|
2014-09-06 03:17:51 -07:00 |
|
Wes Kocher
|
6e24e97e5b
|
Merge inbound to m-c a=merge
|
2014-09-05 19:04:52 -07:00 |
|
Monica Chew
|
5c0326bb2b
|
Bug 1030135: Enable pinning on services.mozilla.com in test mode (r=keeler,a=kwierso)
|
2014-09-05 12:04:26 -07:00 |
|
David Keeler
|
67aa5d4e20
|
bug 1046221 - make nsCryptoHMAC and nsCryptoHash actually check for NSS shutdown r=rbarnes
|
2014-09-05 11:04:22 -07:00 |
|
Monica Chew
|
c1f1fb37b4
|
Bug 1030135: Enable pinning on services.mozilla.com in test mode (r=keeler)
|
2014-09-05 12:04:26 -07:00 |
|
Brian Smith
|
493b0e85e9
|
Bug 1061021, Part 15: Stop using PLArenaPool in CreateEncodedOCSPResponse, r=keeler
--HG--
extra : rebase_source : 00c3f77cd1e7e0d81b0acac84631b81e4cac59bd
|
2014-09-01 19:23:01 -07:00 |
|
Brian Smith
|
713b17fe03
|
Bug 1061021, Part 14: Stop using PLArenaPool in CreateEncodedCertificate, r=keeler
--HG--
extra : rebase_source : 46c292a31fbc4bb7242c93d0d47479600f379323
|
2014-08-30 23:09:18 -07:00 |
|
Brian Smith
|
cf4c572f2d
|
Bug 1061021, Part 10: Stop using PLArenaPool for extension encoding, r=keeler
--HG--
extra : rebase_source : 02b6dcc97204c04ec35b214ea2ce4b9297c78612
|
2014-08-30 19:16:24 -07:00 |
|
David Keeler
|
eebd63d1c8
|
bug 775370 - (part 2/2) use DataStorage as back-end to nsSiteSecurityService r=briansmith
|
2014-09-04 10:42:31 -07:00 |
|
David Keeler
|
4489da0353
|
bug 1057123 - mozilla::pkix: allow end-entity certificates to assert keyCertSign in some cases r=briansmith
|
2014-09-03 10:12:55 -07:00 |
|
Mike Hommey
|
92deb5899a
|
Bug 1059113 - Use templates for shared libraries and frameworks. r=gps
Also force to use the existing template for XPCOM components.
|
2014-09-04 09:04:45 +09:00 |
|
Mike Hommey
|
c2a27deef9
|
Bug 1059090 - Don't require SOURCES to be set for CPP_UNIT_TESTS and SIMPLE_PROGRAMS. r=mshal
|
2014-09-03 14:16:37 +09:00 |
|
Mike Hommey
|
8fd95ad480
|
Bug 1041941 - Use templates for programs, simple programs, libraries and C++ unit tests. r=gps
|
2014-09-03 14:10:54 +09:00 |
|
David Keeler
|
f11a2f12e4
|
bug 1050546 - telemetry for baseline requirements sections 9.2.1 and 9.2.2 (subject alt names/common name) r=rbarnes
|
2014-09-03 11:44:08 -07:00 |
|
Ehsan Akhgari
|
0bb4bc0fc7
|
Bug 1061942 - Switch back security/certverifier and security/manager to use unified builds; r=bsmith
|
2014-09-02 18:28:11 -04:00 |
|
Wes Kocher
|
0ea7f629ad
|
Backed out 1 changesets (bug 1050546) for build bustage
Backed out changeset c7a9e8177202 (bug 1050546)
|
2014-09-02 16:49:51 -07:00 |
|
David Keeler
|
b4c5f35fab
|
bug 1050546 - telemetry for baseline requirements sections 9.2.1 and 9.2.2 (subject alt names/common name) r=rbarnes
|
2014-09-02 12:10:47 -07:00 |
|
Ehsan Akhgari
|
6d473e5bb2
|
Bug 1061061 - Fix more bad implicit constructors in misc. code; r=bsmedberg
|
2014-09-02 18:24:24 -04:00 |
|
Trevor Saunders
|
e1a88eb1fb
|
bug 1059490 - mark more classes MOZ_FINAL r=froydnj
|
2014-08-27 14:26:48 -04:00 |
|
Martin Thomson
|
06a8dbb5bb
|
Bug 1036737 - Adding fallback SCSV use. r=dkeeler
|
2014-08-29 14:59:00 +02:00 |
|
Ehsan Akhgari
|
bfbe81a6e8
|
Bug 1060975 - Fix bad implicit constructors in security; r=bsmith
|
2014-08-31 19:26:27 -04:00 |
|
Ryan VanderMeulen
|
099d0b7caa
|
Merge inbound to m-c. a=merge
|
2014-08-30 12:25:27 -04:00 |
|
ffxbld
|
6202875c3d
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-456 - a=hpkp-update
|
2014-08-30 03:23:01 -07:00 |
|
ffxbld
|
3520eb2656
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-456 - a=hsts-update
|
2014-08-30 03:22:59 -07:00 |
|
David Keeler
|
b7c8a34de5
|
bug 1009161 - follow-up: add test_nsCertType.js to xpcshell.ini so it'll actually run r=mmc
|
2014-08-28 11:38:31 -07:00 |
|
Trevor Saunders
|
2fab17160c
|
bug 1058925 - don't convert nullptr to bool in ClientAuthServer.cpp r=keeler
|
2014-08-27 19:12:22 -04:00 |
|
Monica Chew
|
c8368e00b6
|
Bug 1004781: Enable pinning in test mode for facebook (r=cviecco)
|
2014-08-27 14:18:25 -07:00 |
|
Brian Smith
|
da8027c6e3
|
Bug 1053924: Remove dependencies on PRTime in mozilla::pkix's test code, r=keeler
--HG--
extra : rebase_source : deb2dcec5c56ef86d95df319b5a61165d9d761a7
|
2014-08-08 10:33:18 -07:00 |
|
Cykesiopka
|
7cfa5061fa
|
Bug 1052529 - Add missing l10n strings for mozilla::pkix errors. r=keeler
|
2014-08-26 00:03:00 +02:00 |
|
Birunthan Mohanathas
|
d41e6af583
|
Bug 1045801 - Rename SafeCast to AssertedCast. r=Waldo
|
2014-08-25 12:17:32 -07:00 |
|
David Keeler
|
46ef414d15
|
bug 1034124 - allow overrides when a CA cert is used as an end-entity cert r=briansmith
|
2014-08-22 12:07:08 -07:00 |
|
David Keeler
|
0eb37ae230
|
bug 1009161 - mozilla::pkix: allow the Netscape certificate type extension if more standardized information is present r=briansmith
|
2014-08-25 09:25:36 -07:00 |
|
Ryan VanderMeulen
|
3b99d0fa33
|
Merge inbound to m-c. a=merge
CLOSED TREE
|
2014-08-25 11:49:37 -04:00 |
|
ffxbld
|
64ad26e1d8
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-317 - a=hpkp-update
|
2014-08-23 03:29:03 -07:00 |
|
ffxbld
|
83a687bab5
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-317 - a=hsts-update
|
2014-08-23 03:29:01 -07:00 |
|
Trevor Saunders
|
b6b2d4b019
|
bug 1047696 - mark a number of classes MOZ_FINAL to get compilers to devirtualize more r=froydnj
|
2014-08-05 13:33:55 -04:00 |
|
Camilo Viecco
|
fb4abcd235
|
Bug 1047177 - Treat v4 certs as v3 certs. Tests (2/2). r=keeler.
--HG--
extra : rebase_source : 58be8a1ac652636fea80e83fc8eae2b7092c6edd
|
2014-08-21 14:49:00 -07:00 |
|
David Keeler
|
5e74a22cf3
|
bug 1049095 - re-verify joinee certificate with joining hostname when joining connections r=briansmith r=mcmanus r=cviecco r=mmc r=rbarnes
|
2014-08-21 10:37:23 -07:00 |
|
Patrick McManus
|
a60717f569
|
bug 1050063 - consider tls client hello version in alpn/npn offer list r=hurley r=keeler
|
2014-08-15 09:39:53 -04:00 |
|
Olli Pettay
|
ceb34d2d4a
|
Bug 314095 - Eliminate nsIContent::GetDocument, r=jst
--HG--
extra : rebase_source : dd8f690940825b298a478b65b68a57418a9962ff
|
2014-08-22 23:11:27 +03:00 |
|
David Keeler
|
c23e7f1e8e
|
bug 1057128 - add --clobber to generate_certs.sh, disabled by default (don't unnecessarily regenerate all certificates) r=rbarnes DONTBUILD because NPOTB
|
2014-08-22 10:25:46 -07:00 |
|
David Keeler
|
0973480e83
|
bug 775370 - (part 1/2) introduce DataStorage r=froydnj r=mmc
|
2013-09-09 13:37:21 -07:00 |
|
Ryan VanderMeulen
|
20f7e61cab
|
Merge inbound to m-c. a=merge
|
2014-08-16 17:42:29 -04:00 |
|
ffxbld
|
db7b23ef70
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-329 - a=hpkp-update
|
2014-08-16 03:15:25 -07:00 |
|
ffxbld
|
50cf45e220
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-329 - a=hsts-update
|
2014-08-16 03:15:23 -07:00 |
|
Garrett Robinson
|
e2eed40254
|
Bug 1029155 - Tests for storing failed certificate chains r=keeler
|
2014-08-15 11:27:31 -07:00 |
|
Garrett Robinson
|
45cc1d6a0d
|
Bug 1029155 - Store peer certificate chain from failed connections on TransportSecurityInfo r=keeler
|
2014-08-15 11:27:22 -07:00 |
|
Cykesiopka
|
60bbf0d3c1
|
Bug 1052257 - Add and use error code specific to inadequate key sizes. r=keeler
|
2014-08-12 22:24:00 -04:00 |
|
David Keeler
|
e3f3105dab
|
bug 1030963 - remove non-standard window.crypto functions/properties r=jst r=briansmith r=glandium
|
2014-08-14 09:38:42 -07:00 |
|
David Keeler
|
fb25ddfa4c
|
bug 1040446 - mozilla::pkix: add error code for CA cert used as end-entity cert r=briansmith
|
2014-08-11 12:35:45 -07:00 |
|
Patrick McManus
|
b188053ee8
|
bug 1040323 - SecureBrowserUI needs to consider scheme, not just security of connection r=dkeeler
|
2014-07-28 14:37:41 -04:00 |
|
Ryan VanderMeulen
|
3936db664b
|
Merge inbound to m-c. a=merge
|
2014-08-09 11:19:46 -04:00 |
|
ffxbld
|
d5b7eb5959
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-011 - a=hpkp-update
|
2014-08-09 03:14:42 -07:00 |
|
ffxbld
|
a49d37422d
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-011 - a=hsts-update
|
2014-08-09 03:14:40 -07:00 |
|
J. Ryan Stinnett
|
951ce56ee2
|
Bug 1040130 - Allow specifying a client cert for sockets. r=keeler, r=mcmanus
|
2014-08-07 16:32:00 -04:00 |
|