New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 737411 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Jun 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Remove Thawte and Geotrust from the Dropbox pinlist

Reported by akh...@dropbox.com, Jun 28 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.104 Safari/537.36

Steps to reproduce the problem:
This is a request to update https://cs.chromium.org/chromium/src/net/http/transport_security_state_static.json?maxsize=4939272&l=157 and remove Thawte and Geotrust from the list.

What is the expected behavior?

What went wrong?
We are updating our CA policies and want to remove these CAs from our trust list.

Did this work before? N/A 

Does this work in other browsers? N/A

Chrome version: 59.0.3071.104  Channel: n/a
OS Version: OS X 10.12.5
Flash Version:
 

Comment 1 by akh...@dropbox.com, Jun 28 2017

wow. .. just realized I forgot to say "for the Dropbox pinlist" in the bug report. Sorry about that!

Comment 2 by rsesek@chromium.org, Jun 28 2017

Components: Internals>Network>DomainSecurityPolicy
Labels: -OS-Mac
Owner: lgar...@chromium.org
Status: Assigned (was: Unconfirmed)
Status: Started (was: Assigned)
Summary: Remove Thawte and Geotrust from the Dropbox pinlist (was: Remove Thawte and Geotrust from pinlist for Dropbox.com)
https://chromium-review.googlesource.com/#/c/553540/
Project Member

Comment 4 by bugdroid1@chromium.org, Jun 29 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/faa6704b4206ac30e65740f1f6fd708cc6e9a9d3

commit faa6704b4206ac30e65740f1f6fd708cc6e9a9d3
Author: Lucas Garron <lgarron@chromium.org>
Date: Thu Jun 29 20:16:23 2017

Remove Thawte and Geotrust from the Dropbox preloaded pinset.

No other pinsets use the Thawte roots, so they are also removed from the pins file.

Bug:  737411 
Change-Id: Iaa6f7b3991796b964d406b408e179521e1e408b1
Reviewed-on: https://chromium-review.googlesource.com/553540
Reviewed-by: Ryan Sleevi <rsleevi@chromium.org>
Commit-Queue: Lucas Garron <lgarron@chromium.org>
Cr-Commit-Position: refs/heads/master@{#483463}
[modify] https://crrev.com/faa6704b4206ac30e65740f1f6fd708cc6e9a9d3/net/http/transport_security_state_static.json
[modify] https://crrev.com/faa6704b4206ac30e65740f1f6fd708cc6e9a9d3/net/http/transport_security_state_static.pins

Status: fix (was: Started)
Status: Fixed (was: Fix)

Comment 7 by akh...@dropbox.com, Jun 29 2017

thank you!

Sign in to add a comment