New issue
Advanced search Search tips

Issue 843217 link

Starred by 2 users

Issue metadata

Status: Available
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Task



Sign in to add a comment

Add more robust OCSP fetching tests

Project Member Reported by rsleevi@chromium.org, May 15 2018

Issue description

Based on code coverage from the Linux bots, there's opportunity to improve our testing story for OCSP.

1. Hanging OCSP response (timeout)
2. Shutting down the network stack while there are still pending OCSP requests.
3. OCSP responders that do redirects to non-HTTP endpoints
4. OCSP responders on HTTPS
5. OCSP response bodies that are larger than our maximum permitted response size
6. OCSP responders that just hang-up on us (don't provide an HTTP response code)
7. Our OCSP responder rewriter for the Network Solutions certs
 
For our internal implementation (CertNetFetcher)

1) Fetching CRLs
2) Fetching OCSP

Comment 2 by mattm@chromium.org, May 17 2018

fwiw, may be a few bits that are tested but just not on the coverage dashboard, since os_fuschia is the only platform currently using CertVerifyProcBuiltin as the default verifier. (Ex, CertNetFetcher OCSP fetching should be tested by HTTPSOCSPTest.Intermediate*)

Sign in to add a comment