Patrick McManus
|
39d073c8d5
|
bug 1003448 - HTTP/2 Alternate Service and Opportunistic Security [1/2 PSM] r=keeler
|
2014-08-20 16:30:16 -04:00 |
|
Martin Thomson
|
1e1716e492
|
Bug 1072382 - Remove version intolerance marker on inappropriate_fallback alert, r=keeler
|
2014-10-02 10:03:30 -07:00 |
|
Carsten "Tomcat" Book
|
b37ac43e39
|
merge fx-team to mozilla-central a=merge
|
2014-09-30 15:10:47 +02:00 |
|
Cykesiopka
|
3ac8cb4ccb
|
Bug 1073865 - Add missing SSL_ERROR l10n strings v1. r=dkeeler
|
2014-09-27 14:02:00 +02:00 |
|
Camilo Viecco
|
886005b84a
|
Bug 787133 - (hpkp) Part 2/2. Tests r=keeler
|
2014-09-29 20:31:08 -07:00 |
|
Stephen Pohl
|
579061de7c
|
Mac v2 signing - Bug 1060562 - Update xpcshell-tests for the new v2 bundle structure on OSX. r=jmaher
|
2014-09-29 11:51:29 -07:00 |
|
ffxbld
|
a310d15a38
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-046 - a=hpkp-update
|
2014-09-27 03:16:58 -07:00 |
|
ffxbld
|
bca9d93656
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-046 - a=hsts-update
|
2014-09-27 03:16:56 -07:00 |
|
David Keeler
|
863d5f9477
|
bug 1071308 - (1/2) rename pinning_enforcement_level to PinningMode for brevity r=cviecco
|
2014-09-25 11:08:36 -07:00 |
|
Camilo Viecco
|
c2c7007b5f
|
Bug 787133 - (hpkp) Part 1/2. Header Parsing and interface within PSM. r=keeler, r=mcmanus
|
2014-09-03 10:24:12 -07:00 |
|
Richard Barnes
|
f07a938b7c
|
Bug 1045973 - sec_error_extension_value_invalid: mozilla::pkix does not accept certificates with x509v3 extensions in x509v1 or x509v2 certificates r=keeler
|
2014-09-23 16:48:54 -04:00 |
|
Ehsan Akhgari
|
6b1b9962f5
|
Fix more bad implicit constructors in security, blanket-rs=bsmith, no bug
|
2014-09-23 09:13:26 -04:00 |
|
Vlatko Markovic
|
8818f4947f
|
Bug 1059216 - Verification of Trusted Hosted Apps manifest signature, part 1. r=dkeeler,rlb
|
2014-09-22 07:58:59 -07:00 |
|
Robin Thunell
|
2915e7de92
|
Bug 1059208 - Add scripts for signing manifest files of Trusted Hosted Apps r=dkeeler
|
2014-09-22 07:58:59 -07:00 |
|
ffxbld
|
976d004bf3
|
No bug, Automated HPKP preload list update from host b-linux64-ix-0007 - a=hpkp-update
|
2014-09-20 03:17:29 -07:00 |
|
ffxbld
|
c78690b02d
|
No bug, Automated HSTS preload list update from host b-linux64-ix-0007 - a=hsts-update
|
2014-09-20 03:17:26 -07:00 |
|
Arthur Edelstein
|
cb0c9e468d
|
Bug 967977 - Add pref to disable session identifiers (session tickets and session IDs). r=dkeeler
|
2014-09-08 15:32:00 -04:00 |
|
Patrick McManus
|
235b069e72
|
bug 1003448 - HTTP/2 Alternate Service and Opportunistic Security [1/2 PSM] r=keeler
|
2014-08-20 16:30:16 -04:00 |
|
Martin Thomson
|
36ef87e623
|
Bug 1075991 - Tracking cause of inappropriate TLS version fallback, r=keeler
|
2014-10-03 11:01:24 -07:00 |
|
Martin Thomson
|
e3fc75fe11
|
Bug 1075991 - Remember version intolerance reason code, r=keeler
|
2014-10-03 11:01:24 -07:00 |
|
Monica Chew
|
af2478ad59
|
Bug 1030135: Set is_moz if the pinset name contains mozilla, set bucket id for pinsets containing the string mozilla (r=keeler)
|
2014-10-02 16:45:13 -07:00 |
|
J.C. Jones
|
e75e48ed45
|
Bug 1054498 - Report pinning violations by CA r=keeler
|
2014-10-17 10:33:50 -07:00 |
|
Carsten "Tomcat" Book
|
d893b9cc90
|
Backed out changeset f5fa8ea86d3b (bug 622859)
|
2014-10-17 13:13:01 +02:00 |
|
Cykesiopka
|
ef48a9fa7c
|
Bug 622859 - Tests for bug 622859. r=briansmith,keeler
|
2014-10-16 05:22:00 +02:00 |
|
David Keeler
|
d44051d068
|
bug 1055238 - add nsNSSCertListFakeTransport so nsIX509CertList can survive the child process r=rbarnes
|
2014-09-16 15:49:37 -07:00 |
|
David Keeler
|
76d5bfab7d
|
bug 1055238 - clean up nsNSSCertificateFakeTransport.{cpp,h} for style nits r=rbarnes
|
2014-09-16 13:24:13 -07:00 |
|
Camilo Viecco
|
4782afddb6
|
Bug 787133 - (hpkp) testing of internal storage and idl r=keeler.
--HG--
extra : rebase_source : c4f83f38a3b8f293a1ca61f2f0a6f90df6ff7840
|
2014-09-12 14:59:37 -07:00 |
|
Camilo Viecco
|
d790eb8f88
|
Bug 787133 - (hpkp) Internal storage of hpkp data. r=keeler.
--HG--
extra : rebase_source : 1ef88ab5ebcf9634bd1de76ec1c9543eb87d265b
|
2014-09-12 14:59:37 -07:00 |
|
David Keeler
|
db0e8cfdbd
|
bug 1066190 - ensure that pinning checks are done for otherwise overridable errors r=mmc
|
2014-09-12 13:20:43 -07:00 |
|
Camilo Viecco
|
9a1ec24aef
|
Bug 1067565 - Built-in pins expires decades later. r=keeler
|
2014-09-15 17:17:12 -07:00 |
|
Wes Kocher
|
6e187f49f8
|
Merge m-c to inbound a=merge
|
2014-09-15 16:41:45 -07:00 |
|
ffxbld
|
bed71c1658
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-318 - a=hpkp-update
|
2014-09-15 14:35:39 -07:00 |
|
ffxbld
|
cc3388a150
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-318 - a=hsts-update
|
2014-09-15 14:35:37 -07:00 |
|
David Keeler
|
dce41c469b
|
bug 973048 - follow-up to add another missed #include r=bustage on a CLOSED TREE
|
2014-09-15 13:50:18 -07:00 |
|
David Keeler
|
c6dc096f07
|
bug 973048 - follow-up to add #include for ScopedPtr r=bustage on a CLOSED TREE
|
2014-09-15 13:02:47 -07:00 |
|
David Keeler
|
4113b4b466
|
bug 973048 - replace nsNSSCleaner with Scoped types r=rbarnes
|
2014-09-15 12:31:43 -07:00 |
|
Carsten "Tomcat" Book
|
d557d05d44
|
merge m-i to m-c a=merge
|
2014-09-12 15:07:38 +02:00 |
|
ffxbld
|
7d604b16de
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-021 - a=hpkp-update
|
2014-09-11 20:51:37 -07:00 |
|
ffxbld
|
44fa5fca8f
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-021 - a=hsts-update
|
2014-09-11 20:51:35 -07:00 |
|
Giovanni Sferro
|
ccbb9be8bc
|
Bug 1050518 - Remove nsICertificatePrincipal. r=keeler
|
2014-09-10 20:31:00 -04:00 |
|
Brian Smith
|
8dbcf66d66
|
Bug 1063006: Centralize direct use of NSS for crypto in the mozilla::pkix test suite, r=keeler
--HG--
rename : security/pkix/test/lib/pkixtestutil.cpp => security/pkix/test/lib/pkixtestnss.cpp
extra : rebase_source : 93515d39abf91168fa86268f9b26f8c62d0d411e
|
2014-08-31 17:47:09 -07:00 |
|
Ehsan Akhgari
|
bd73520e3c
|
Bug 1064356 - Fix more bad implicit constructors in security; r=bsmith
|
2014-09-08 20:47:36 -04:00 |
|
David Keeler
|
d577ecb4c1
|
bug 1004781 - follow-up to add "DigiCert ECC Secure Server CA" to Facebook's pinset r=mmc
|
2014-09-08 09:33:03 -07:00 |
|
Carsten "Tomcat" Book
|
75dcdffdac
|
merge mozilla-inbound to mozilla-central a=merge
|
2014-09-08 15:22:16 +02:00 |
|
ffxbld
|
fb37ddfbb4
|
No bug, Automated HPKP preload list update from host b-linux64-ix-0009 - a=hpkp-update
|
2014-09-06 03:17:54 -07:00 |
|
ffxbld
|
335a88aab5
|
No bug, Automated HSTS preload list update from host b-linux64-ix-0009 - a=hsts-update
|
2014-09-06 03:17:51 -07:00 |
|
Wes Kocher
|
ca62a34614
|
Merge inbound to m-c a=merge
|
2014-09-05 19:04:52 -07:00 |
|
Monica Chew
|
573218568c
|
Bug 1030135: Enable pinning on services.mozilla.com in test mode (r=keeler,a=kwierso)
|
2014-09-05 12:04:26 -07:00 |
|
David Keeler
|
702384684c
|
bug 1046221 - make nsCryptoHMAC and nsCryptoHash actually check for NSS shutdown r=rbarnes
|
2014-09-05 11:04:22 -07:00 |
|
Monica Chew
|
2c36fac925
|
Bug 1030135: Enable pinning on services.mozilla.com in test mode (r=keeler)
|
2014-09-05 12:04:26 -07:00 |
|
Brian Smith
|
26f076840d
|
Bug 1061021, Part 15: Stop using PLArenaPool in CreateEncodedOCSPResponse, r=keeler
--HG--
extra : rebase_source : 00c3f77cd1e7e0d81b0acac84631b81e4cac59bd
|
2014-09-01 19:23:01 -07:00 |
|
Brian Smith
|
1966d956d1
|
Bug 1061021, Part 14: Stop using PLArenaPool in CreateEncodedCertificate, r=keeler
--HG--
extra : rebase_source : 46c292a31fbc4bb7242c93d0d47479600f379323
|
2014-08-30 23:09:18 -07:00 |
|
Brian Smith
|
dedfff0a81
|
Bug 1061021, Part 10: Stop using PLArenaPool for extension encoding, r=keeler
--HG--
extra : rebase_source : 02b6dcc97204c04ec35b214ea2ce4b9297c78612
|
2014-08-30 19:16:24 -07:00 |
|
David Keeler
|
d219ed0d80
|
bug 775370 - (part 2/2) use DataStorage as back-end to nsSiteSecurityService r=briansmith
|
2014-09-04 10:42:31 -07:00 |
|
David Keeler
|
a250e4de47
|
bug 1057123 - mozilla::pkix: allow end-entity certificates to assert keyCertSign in some cases r=briansmith
|
2014-09-03 10:12:55 -07:00 |
|
Mike Hommey
|
4b99580194
|
Bug 1059113 - Use templates for shared libraries and frameworks. r=gps
Also force to use the existing template for XPCOM components.
|
2014-09-04 09:04:45 +09:00 |
|
Mike Hommey
|
0060683747
|
Bug 1059090 - Don't require SOURCES to be set for CPP_UNIT_TESTS and SIMPLE_PROGRAMS. r=mshal
|
2014-09-03 14:16:37 +09:00 |
|
Mike Hommey
|
ed70c5f377
|
Bug 1041941 - Use templates for programs, simple programs, libraries and C++ unit tests. r=gps
|
2014-09-03 14:10:54 +09:00 |
|
David Keeler
|
c1853c5db4
|
bug 1050546 - telemetry for baseline requirements sections 9.2.1 and 9.2.2 (subject alt names/common name) r=rbarnes
|
2014-09-03 11:44:08 -07:00 |
|
Ehsan Akhgari
|
6deacdf4e9
|
Bug 1061942 - Switch back security/certverifier and security/manager to use unified builds; r=bsmith
|
2014-09-02 18:28:11 -04:00 |
|
Wes Kocher
|
c0770e9a92
|
Backed out 1 changesets (bug 1050546) for build bustage
Backed out changeset c7a9e8177202 (bug 1050546)
|
2014-09-02 16:49:51 -07:00 |
|
David Keeler
|
18cd42500e
|
bug 1050546 - telemetry for baseline requirements sections 9.2.1 and 9.2.2 (subject alt names/common name) r=rbarnes
|
2014-09-02 12:10:47 -07:00 |
|
Ehsan Akhgari
|
5bffafdd26
|
Bug 1061061 - Fix more bad implicit constructors in misc. code; r=bsmedberg
|
2014-09-02 18:24:24 -04:00 |
|
Trevor Saunders
|
d75ed5bf7f
|
bug 1059490 - mark more classes MOZ_FINAL r=froydnj
|
2014-08-27 14:26:48 -04:00 |
|
Martin Thomson
|
7e9f88e039
|
Bug 1036737 - Adding fallback SCSV use. r=dkeeler
|
2014-08-29 14:59:00 +02:00 |
|
Ehsan Akhgari
|
aafc47e9e9
|
Bug 1060975 - Fix bad implicit constructors in security; r=bsmith
|
2014-08-31 19:26:27 -04:00 |
|
Ryan VanderMeulen
|
c30a1809d2
|
Merge inbound to m-c. a=merge
|
2014-08-30 12:25:27 -04:00 |
|
ffxbld
|
61a875d894
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-456 - a=hpkp-update
|
2014-08-30 03:23:01 -07:00 |
|
ffxbld
|
ea9d818f0d
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-456 - a=hsts-update
|
2014-08-30 03:22:59 -07:00 |
|
David Keeler
|
4b04dd58f3
|
bug 1009161 - follow-up: add test_nsCertType.js to xpcshell.ini so it'll actually run r=mmc
|
2014-08-28 11:38:31 -07:00 |
|
Trevor Saunders
|
fd5e2abf5a
|
bug 1058925 - don't convert nullptr to bool in ClientAuthServer.cpp r=keeler
|
2014-08-27 19:12:22 -04:00 |
|
Monica Chew
|
5c4a88776f
|
Bug 1004781: Enable pinning in test mode for facebook (r=cviecco)
|
2014-08-27 14:18:25 -07:00 |
|
Brian Smith
|
01f0b82f34
|
Bug 1053924: Remove dependencies on PRTime in mozilla::pkix's test code, r=keeler
--HG--
extra : rebase_source : deb2dcec5c56ef86d95df319b5a61165d9d761a7
|
2014-08-08 10:33:18 -07:00 |
|
Cykesiopka
|
bfd5ec525f
|
Bug 1052529 - Add missing l10n strings for mozilla::pkix errors. r=keeler
|
2014-08-26 00:03:00 +02:00 |
|
Birunthan Mohanathas
|
77bfad00a6
|
Bug 1045801 - Rename SafeCast to AssertedCast. r=Waldo
|
2014-08-25 12:17:32 -07:00 |
|
David Keeler
|
d026d78753
|
bug 1034124 - allow overrides when a CA cert is used as an end-entity cert r=briansmith
|
2014-08-22 12:07:08 -07:00 |
|
David Keeler
|
800c5b4b9f
|
bug 1009161 - mozilla::pkix: allow the Netscape certificate type extension if more standardized information is present r=briansmith
|
2014-08-25 09:25:36 -07:00 |
|
Ryan VanderMeulen
|
81342753e0
|
Merge inbound to m-c. a=merge
CLOSED TREE
|
2014-08-25 11:49:37 -04:00 |
|
ffxbld
|
07de5c29aa
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-317 - a=hpkp-update
|
2014-08-23 03:29:03 -07:00 |
|
ffxbld
|
8f1e08d168
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-317 - a=hsts-update
|
2014-08-23 03:29:01 -07:00 |
|
Trevor Saunders
|
fd5e9d1fcc
|
bug 1047696 - mark a number of classes MOZ_FINAL to get compilers to devirtualize more r=froydnj
|
2014-08-05 13:33:55 -04:00 |
|
Camilo Viecco
|
4c5f0ef40a
|
Bug 1047177 - Treat v4 certs as v3 certs. Tests (2/2). r=keeler.
--HG--
extra : rebase_source : 58be8a1ac652636fea80e83fc8eae2b7092c6edd
|
2014-08-21 14:49:00 -07:00 |
|
David Keeler
|
1f84bc411b
|
bug 1049095 - re-verify joinee certificate with joining hostname when joining connections r=briansmith r=mcmanus r=cviecco r=mmc r=rbarnes
|
2014-08-21 10:37:23 -07:00 |
|
Patrick McManus
|
300766f367
|
bug 1050063 - consider tls client hello version in alpn/npn offer list r=hurley r=keeler
|
2014-08-15 09:39:53 -04:00 |
|
Olli Pettay
|
d72906c30d
|
Bug 314095 - Eliminate nsIContent::GetDocument, r=jst
--HG--
extra : rebase_source : dd8f690940825b298a478b65b68a57418a9962ff
|
2014-08-22 23:11:27 +03:00 |
|
David Keeler
|
4ee21d300f
|
bug 1057128 - add --clobber to generate_certs.sh, disabled by default (don't unnecessarily regenerate all certificates) r=rbarnes DONTBUILD because NPOTB
|
2014-08-22 10:25:46 -07:00 |
|
David Keeler
|
3e8057dc3d
|
bug 775370 - (part 1/2) introduce DataStorage r=froydnj r=mmc
|
2013-09-09 13:37:21 -07:00 |
|
Ryan VanderMeulen
|
5fe0932115
|
Merge inbound to m-c. a=merge
|
2014-08-16 17:42:29 -04:00 |
|
ffxbld
|
e3b3b65eb1
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-329 - a=hpkp-update
|
2014-08-16 03:15:25 -07:00 |
|
ffxbld
|
93cb810873
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-329 - a=hsts-update
|
2014-08-16 03:15:23 -07:00 |
|
Garrett Robinson
|
90fa6beb03
|
Bug 1029155 - Tests for storing failed certificate chains r=keeler
|
2014-08-15 11:27:31 -07:00 |
|
Garrett Robinson
|
691dcd68c1
|
Bug 1029155 - Store peer certificate chain from failed connections on TransportSecurityInfo r=keeler
|
2014-08-15 11:27:22 -07:00 |
|
Cykesiopka
|
f4a67332e8
|
Bug 1052257 - Add and use error code specific to inadequate key sizes. r=keeler
|
2014-08-12 22:24:00 -04:00 |
|
David Keeler
|
c3d3df58ac
|
bug 1030963 - remove non-standard window.crypto functions/properties r=jst r=briansmith r=glandium
|
2014-08-14 09:38:42 -07:00 |
|
David Keeler
|
3d57f23fab
|
bug 1040446 - mozilla::pkix: add error code for CA cert used as end-entity cert r=briansmith
|
2014-08-11 12:35:45 -07:00 |
|
Patrick McManus
|
b82e230f36
|
bug 1040323 - SecureBrowserUI needs to consider scheme, not just security of connection r=dkeeler
|
2014-07-28 14:37:41 -04:00 |
|
Ryan VanderMeulen
|
0e89667592
|
Merge inbound to m-c. a=merge
|
2014-08-09 11:19:46 -04:00 |
|
ffxbld
|
40f698d0cb
|
No bug, Automated HPKP preload list update from host bld-linux64-spot-011 - a=hpkp-update
|
2014-08-09 03:14:42 -07:00 |
|
ffxbld
|
509bcaeb60
|
No bug, Automated HSTS preload list update from host bld-linux64-spot-011 - a=hsts-update
|
2014-08-09 03:14:40 -07:00 |
|
J. Ryan Stinnett
|
ce8794da11
|
Bug 1040130 - Allow specifying a client cert for sockets. r=keeler, r=mcmanus
|
2014-08-07 16:32:00 -04:00 |
|