New issue
Advanced search Search tips

Issue 844069 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 3
Type: Bug



Sign in to add a comment

Block locally-installed hardcoded CA for Mitel VOIP Products

Project Member Reported by awhalley@google.com, May 17 2018

Issue description

Mitel released a security advisory in 2017 advising customers to uninstall this CA and we have observed evidence of this CA being used to maliciously issue Man-in-the-Middle (MITM) certificates, including www.google.com. While this CA is not publicly-trusted as a part of the webPKI, its relative ubiquity and demonstrable misuse warrant protecting Chrome users by blocking trust in it.
 

Comment 1 by awhalley@google.com, May 17 2018

Labels: ReleaseBlock-Beta M-68 OS-Android OS-Chrome OS-Fuchsia OS-Linux OS-Mac OS-Windows
Friendly ping to get an update on this issue as it is marked as RBB.
Thanks..!

Comment 3 by awhalley@google.com, May 22 2018

Cc: -awhalley@chromium.org sleevi@google.com
Owner: awhalley@chromium.org
I'm still trying to get in touch with Mitel. I'll take the bug as I continue to do that, as it predicates any other action.
Cc: -sleevi@google.com asymmetric@chromium.org rsleevi@chromium.org
Your bug is tagged as Release block Beta and we are branching in 2 days.Please have a fix ASAP.

Comment 6 by awhalley@google.com, May 22 2018

Labels: -ReleaseBlock-Beta ReleaseBlock-Stable
Needn't block the first beta (though we'd like to get it into an early one) - moving to RBS
Status: Assigned (was: Untriaged)
As per C#6, assigning to owner.
As the owner ( awhalley@) last visit shown as 18 days ago, could someone from cc'ed dev please take a look into it.

Thanks..!
(Visiting from my chromium.org account to reset that flag!)

I've contacted a human at Mitel, currently waiting for a response.

Friendly ping to get an update on this issue as it is marked as RBS.
Thanks..!
Labels: -ReleaseBlock-Stable -M-68 M-69
Thanks for the ping. Change is up for review, but at this point it's probably best to just slip to 69.
Project Member

Comment 12 by bugdroid1@chromium.org, Jun 19 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/211c7979fe5bcef296ca35dfa85a5aa82f65a25c

commit 211c7979fe5bcef296ca35dfa85a5aa82f65a25c
Author: Andrew R. Whalley <awhalley@google.com>
Date: Tue Jun 19 05:12:18 2018

Blacklist potentially compromised Mitel keys

See https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-17-0001

Bug= 844069 

Change-Id: I0c7597689981279b3a260f4c3c7d681529b22a01
Reviewed-on: https://chromium-review.googlesource.com/1103224
Commit-Queue: Andrew Whalley <awhalley@google.com>
Reviewed-by: Ryan Sleevi <rsleevi@chromium.org>
Cr-Commit-Position: refs/heads/master@{#568348}
[modify] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/cert/cert_verify_proc_blacklist.inc
[add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/2a33f5b48176523fd3c0d854f20093417175bfd498ef354cc7f38b54adabaf1a.pem
[add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/2d11e736f0427fd6ba4b372755d34a0edd8d83f7e9e7f6c01b388c9b7afa850d.pem
[add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/3ab0fcc7287454c405863e3aa204fea8eb0c50a524d2a7e15524a830cd4ab0fe.pem
[add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/60911c79835c3739432d08c45df64311e06985c5889dc5420ce3d142c8c7ef58.pem
[modify] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/README.md

Status: Fixed (was: Assigned)
Project Member

Comment 14 by bugdroid1@chromium.org, Jul 10

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/de70fd58d3349f15fb7c6dfb9589029643d3d6c3

commit de70fd58d3349f15fb7c6dfb9589029643d3d6c3
Author: Emily Stark <estark@google.com>
Date: Tue Jul 10 23:13:00 2018

Show MITM interstitial for blocked compromised Mitel keys

These keys have been blacklisted in https://chromium-review.googlesource.com/1103224. We can use dynamic interstitials to trigger the special MITM interstitial for them. This interstitial can be seen at chrome://interstitials/mitm-software-ssl. It informs the user that there is misconfigured software and that they should contact their network administrator.

Bug:  844069 
Cq-Include-Trybots: luci.chromium.try:closure_compilation
Change-Id: I21a5257f48e88347792e9e5c9ed0d45cfa7f4ee2
Reviewed-on: https://chromium-review.googlesource.com/1132379
Reviewed-by: Mustafa Emre Acer <meacer@chromium.org>
Commit-Queue: Emily Stark <estark@chromium.org>
Cr-Commit-Position: refs/heads/master@{#573969}
[modify] https://crrev.com/de70fd58d3349f15fb7c6dfb9589029643d3d6c3/chrome/browser/resources/ssl/ssl_error_assistant/ssl_error_assistant.asciipb

Sign in to add a comment