New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 715460 link

Starred by 4 users

Issue metadata

Status: Verified
Owner:
Closed: May 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Feature



Sign in to add a comment

ONC-provided trust roots should be available in kiosk and AD user sessions

Project Member Reported by atwilson@chromium.org, Apr 26 2017

Issue description

This line of code is overly restrictive: https://cs.chromium.org/chromium/src/chrome/browser/chromeos/policy/user_network_configuration_updater_factory.cc?rcl=c4cb0d38f0bd26578120775e9c09be813b5215c0&l=75

We should probably only exclude certs from public sessions (and possibly add a comment that we should remove that restriction entirely when we fix https://bugs.chromium.org/p/chromium/issues/detail?id=572103)


 

Comment 1 by pmarko@chromium.org, Apr 26 2017

Status: Started (was: Untriaged)
Can you clarify Kiosk/AD user scenarios?

In particular, where I'm going is that if we're talking about concurrent profiles, there's risk. If there's only one of these active at a time, that risk is minimized. I just want to make sure we get that part absolutely right, as the failure mode is not pretty due to NSS's internal global shared structures :)

Comment 3 by pmarko@chromium.org, Apr 26 2017

Status: Assigned (was: Started)

Comment 4 by pmarko@chromium.org, Apr 27 2017

Kiosk does not have concurrent users - the sign-in screen is skipped and the policy-configured kiosk app is displayed. 

AD: I'm not sure - but would
https://cs.chromium.org/chromium/src/chrome/browser/chromeos/login/users/multi_profile_user_controller.cc?rcl=6ad875d22992e6bf124245d186ac9e19fdfafb96&l=148
and
https://cs.chromium.org/chromium/src/chrome/browser/chromeos/policy/policy_cert_service.cc?rcl=6ad875d22992e6bf124245d186ac9e19fdfafb96&l=78
not reduce the multi-profile risk? After all, regular users are also allowed for multi-profile at the moment, so I don't understand the difference.

Thank you!
It's a moot point since we aren't supporting multi-login for AD users. In theory it should be OK as Pavol says because the security/privacy surface is identical between AD and Gaia users, but we can skip that conversation since there's no multi-login.

Comment 7 by pmarko@chromium.org, May 19 2017

Status: Fixed (was: Assigned)
Labels: Chromad

Comment 9 by dchan@chromium.org, Aug 1 2017

Labels: VerifyIn-61

Comment 10 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)
Status: Fixed (was: Archived)
Labels: -Type-Bug -Chromad Type-Feature
verified user is able to push certificates using ONC policy 

veyron tiger on M66 10452.69.0
Status: Verified (was: Fixed)
Also verified for AD sessions (see attached screenshot) on M67 (10575.12.0, 67.0.3396.16) and M68 (10610.0.0, 68.0.3404.0).

Device: Santa
Screenshot 2018-04-23 at 12.35.41 PM.png
97.7 KB View Download

Sign in to add a comment