New issue
Advanced search Search tips

Issue 824888 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Categorize bmoattachments.org in HSTS preload list so it isn't un-preloaded

Reported by apk...@mozilla.com, Mar 22 2018

Issue description

Chrome Version       : (all versions)
URLs (if applicable) : https://hstspreload.org/?domain=bmoattachments.org
Other browsers tested:
  Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
     Safari: FAIL
    Firefox: FAIL
       Edge: FAIL

What steps will reproduce the problem?
(1) https://hstspreload.org/?domain=bmoattachments.org warns about bmoattachments.org
(2)
(3)

What is the expected result?
bmoattachments.org (and all subdomains) should not be marked for possible unpreloading.

Please categorize as policy: custom (or whatever is the correct categorization) so that it doesn't become unlisted.

Thanks so much!

What happens instead?

bmoattachments.org was preloaded some time ago. However, as it is in the public suffix list, the HSTS Preload site now warns:

Status: bmoattachments.org is currently preloaded, but no longer meets the requirements. It may be at risk of removal.


Please provide any additional information below. Attach a screenshot if
possible.

Open bug in Bugzilla:

https://bugzilla.mozilla.org/show_bug.cgi?id=1448105
 
Components: Internals>Network>DomainSecurityPolicy
Owner: nhar...@chromium.org
Status: Assigned (was: Unconfirmed)
Project Member

Comment 2 by bugdroid1@chromium.org, Mar 27 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/fc88e337d8c12da35eb9c89a0db1e06e86971291

commit fc88e337d8c12da35eb9c89a0db1e06e86971291
Author: Nick Harper <nharper@chromium.org>
Date: Tue Mar 27 20:29:47 2018

Move bmoattachments.org to the eTLD section of the HSTS Preload list

Bug:  824888 
Change-Id: Ife836938b0a6a1e97c5e838b80ab88511d692e6f
Reviewed-on: https://chromium-review.googlesource.com/980810
Reviewed-by: Eric Lawrence <elawrence@chromium.org>
Cr-Commit-Position: refs/heads/master@{#546236}
[modify] https://crrev.com/fc88e337d8c12da35eb9c89a0db1e06e86971291/net/http/transport_security_state_static.json

Comment 3 by apk...@mozilla.com, Mar 27 2018

Great, thanks so much Nick and Eric!
Status: Fixed (was: Assigned)
hstspreload.org now shows bmoattachments.org as preloaded without any errors or warnings.

Sign in to add a comment