New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 643453 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Nov 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 1
Type: Feature


Participants' hotlists:
HSTS-Preload


Sign in to add a comment

Add meet.google.com to the HSTS preload list

Project Member Reported by q...@chromium.org, Sep 1 2016

Issue description

Same way as the existing hangouts.google.com and talkgadget.google.com.
 

Comment 1 by q...@chromium.org, Sep 1 2016

Labels: -Type-Launch Type-Feature

Comment 2 by q...@chromium.org, Sep 2 2016

Cc: lgar...@chromium.org
Is there any reason to R-V-G this?
Is there any reason (... which sadly, may be the reason to R-V-G this), why we can't use the same as the public mechanisms at https://hstspreload.appspot.com/

Should this be HPKP pinned, as other Google properties are? Presumably, yes, but you can confirm with internal folks if you're not sure (feel free to poke my @google without the r)
Cc: -lgar...@chromium.org
Labels: Hotlist-HSTS-Preload
Owner: lgar...@chromium.org
Status: Assigned (was: Unconfirmed)
I will need to add it to the CL at https://codereview.chromium.org/2282203002

1) {hangouts, talkgadget}.google.com are also pinned. I presume that will be safe here?
2) Any chance you could fix up the errors at https://hstspreload.appspot.com/?domain=meet.google.com ? (Ignore the subdomain error.)
3) Since the draft CL will be public, may I derestrict this bug?

rsleevi@: hstspreload.appspot.com only accepts eTLD+1. Exceptions need manual handling.

Comment 6 by q...@chromium.org, Sep 2 2016

1) Yes, it will be safe.
2) I'm trying to fix it with my pending/latest change (see critique). But essentially this will serve exactly the same thing as the other ones.
3) Yes.

Thanks.
Thanks!

{hangouts, talkgadget}.google.com actually don't send out the preload directive. If you could all change them to send it, that would be good future-proofing.
Labels: -Restrict-View-Google
Status: Started (was: Assigned)
https://codereview.chromium.org/2282203002

Comment 9 by q...@chromium.org, Sep 16 2016

Server-side fixes have been checked in and should be available in about a week. Thanks.
Components: Internals>Network>DomainSecurityPolicy
Components: -Internals>Network>SSL
Labels: M-55
Status: Fixed (was: Started)
Labels: -Hotlist-GoogleApps Hotlist-Partner-GSuite

Sign in to add a comment