New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 601561 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: May 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug


Participants' hotlists:
HSTS-Preload


Sign in to add a comment

Merge preload HSTS preload list removals to M50

Project Member Reported by lgar...@chromium.org, Apr 7 2016

Issue description

From  https://crbug.com/527947#c38  :

--------------------------------

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/253102d2f4b59a803816d2567233a5823ab5d782

commit 253102d2f4b59a803816d2567233a5823ab5d782
Author: lgarron <lgarron@chromium.org>
Date: Thu Apr 07 21:11:53 2016

Remove several domains from the HSTS preload list and remove an extra space.

videomail.io:
> I mistakenly used this code for helmet, a npm package to set various
> HTTP headers:
>
> ```
>         app.use(helmet.hsts({
>           maxAge:            108864000000, // Must be at least 18 weeks to be approved by Google
>           preload:           true
>         }))
> ```
>
> But now, I can't visit the local site with plain HTTP anymore. I need
> that for some tests.

tablotv.com:
> No one from our organization (we are small) added our domain to the list and
> according to the documentation on the HSTS preload site it may take many
> revisions to be removed from the list.
> ...
> As for how it happened, we are not sure.

involved-it.be:
> Several months ago I (accidently) added involved-it.be to the HSTS
> preload list presumably via https://hstspreload.appspot.com/.

bam.com.au: A mail subdomain hosted by a third-party does not support SSL.

logotype.se:
> The reason is that I do development, and for some subdomains I don't
> have TLS setup on the different server instances.

BUG=  527947  
TBR=palmer@chromium.org

Review URL: https://codereview.chromium.org/1814053002

Cr-Commit-Position: refs/heads/master@{#385850}

[modify] https://crrev.com/253102d2f4b59a803816d2567233a5823ab5d782/net/http/transport_security_state_static.h
[modify] https://crrev.com/253102d2f4b59a803816d2567233a5823ab5d782/net/http/transport_security_state_static.json
Labels: Merge-Request-50
I'd like to request a merge of 97d372c2bc6233832ee573db666579ea15209430 [1] and 253102d2f4b59a803816d2567233a5823ab5d782 [2] to Chrome 50.

These commits remove 5 sites from the HSTS preload list. Merging them to Chrome 50 will avoid an additional 6 weeks of breakage for them.

Although the commits contain a large diff of static data, this data is auto-generated using a process that has been working reliably for the last 2 years. Therefore, the merge is semantically equivalent to removing just those 5 sites from transport_security_state_static.json (and fixing a typo).


[1] https://chromium.googlesource.com/chromium/src/+/97d372c2bc6233832ee573db666579ea15209430
[2]  https://crbug.com/601561#c1 
Summary: Merge preload HSTS preload list removals to M50 (was: Merge preload HSTS preload list removals from M50)

Comment 4 by tin...@google.com, Apr 7 2016

Labels: -Merge-Request-50 Merge-Approved-50
Merge approved for M50 (branch 2661). Pls go ahead merge.
Please merge your change to M50 branch 2661 by 5:00 PM PST on April 8th,Friday to make into the desktop Stable final build cut. Thank you.
Labels: Merge-Merged
Merges are visible at 527947, since that was the bug number for the merged commits:

 https://crbug.com/527947#c41  and  https://crbug.com/527947#c42 
Labels: -Merge-Approved-50 merge-merged-2661
Ok, thank you. Seems like already merged to M50 branch 2661, so removing "Merge-Approved-50" label and applying "merge-merged-2661" label.

Status: Fixed (was: Assigned)
Components: Internals>Network>DomainSecurityPolicy

Sign in to add a comment