New issue
Advanced search Search tips

Issue 598109 link

Starred by 10 users

Issue metadata

Status: Verified
Owner:
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Launch-OWP
Launch-Accessibility: ----
Launch-Exp-Leadership: ----
Launch-Leadership: ----
Launch-Legal: ----
Launch-M-Approved: ----
Launch-M-Target: ----
Launch-Privacy: ----
Launch-Security: ----
Launch-Test: ----
Launch-UI: ----
Rollout-Type: ----



Sign in to add a comment

Deprecate DHE-based ciphers

Project Member Reported by davidben@chromium.org, Mar 25 2016

Issue description

(See http://www.chromium.org/blink#launch-process for an overview)

Change description:
Officially deprecate DHE-based ciphers and add a JS console warning in DevTools.
See https://groups.google.com/a/chromium.org/forum/#!msg/security-dev/dYyhKHPnrI0/pNxx8vTKBAAJ for earlier "pre-"Intent. (Will send out another one with the right format to dot i's and cross t's.)

Changes to API surface:
None, just a JS console warning. We'll remove it in a later release.

When DHE is removed, we'll stop advertising DHE-based ciphers. It is expected that the vast majority of DHE-based 

Links:
Public standards discussion: None

Support in other browsers:
Internet Explorer: DHE is still supported
Firefox: DHE is still supported
Safari: DHE has been removed

*Make sure to fill in any labels with a -?, including all OSes this change
affects. Feel free to leave other labels at the defaults.

 
Project Member

Comment 1 by bugdroid1@chromium.org, Apr 3 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/157660a6a5c953b387361c3890cdfa39f042d0e5

commit 157660a6a5c953b387361c3890cdfa39f042d0e5
Author: davidben <davidben@chromium.org>
Date: Sun Apr 03 19:14:33 2016

Add a deprecation warning for DHE.

Link to Intent thread:
https://groups.google.com/a/chromium.org/d/msg/blink-dev/AAdv838-koo/bJv17voIBAAJ

BUG= 598109 
TEST=Visiting https://dh1024.badssl.com/ and opening the JS console shows a deprecation warning.

Review URL: https://codereview.chromium.org/1851203002

Cr-Commit-Position: refs/heads/master@{#384836}

[modify] https://crrev.com/157660a6a5c953b387361c3890cdfa39f042d0e5/chrome/renderer/chrome_render_frame_observer.cc

Cc: awhalley@chromium.org
+awhalley, can we close this one? There's a separate launch bug ( issue #619194 ) for the removal.
Status: Verified (was: Assigned)
Looks good.

Moving to Verified as I've confirmed that I'm seeing the console warning when visiting https://dh2048.badssl.com/ in M51
Project Member

Comment 4 by bugdroid1@chromium.org, Jul 28 2016

Sign in to add a comment