New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 664602 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Dec 2016
Cc:
EstimatedDays: ----
NextAction: 2016-11-14
OS: Android
Pri: 3
Type: Bug



Sign in to add a comment

Support OCSP policy

Project Member Reported by lzia@google.com, Nov 11 2016

Issue description

Add OCSP policy support (http://www.chromium.org/administrators/policy-list-3#EnableOnlineRevocationChecks), in Android.
AOSP added OCSP support N, so it should be possible to add this support based on API level N+.

This is required to meet NIAP certification with Chrome.
 

Comment 1 by bauerb@chromium.org, Nov 23 2016

Cc: aber...@chromium.org
Owner: aber...@chromium.org
Status: Assigned (was: Untriaged)
Cc: -aber...@chromium.org bauerb@chromium.org andyds@google.com rsleevi@chromium.org
Status: WontFix (was: Assigned)
We will not be supporting OCSP on Android. As discussed offline it adds little, if any, extra security, and can lead to long delays (100s of ms when successful, up to 30s for some failure cases). It is unclear whether implementing this within Chrome would meet the NIAP requirements. 

Sign in to add a comment