Block locally-installed hardcoded CA for Mitel VOIP Products |
|||||||
Issue descriptionMitel released a security advisory in 2017 advising customers to uninstall this CA and we have observed evidence of this CA being used to maliciously issue Man-in-the-Middle (MITM) certificates, including www.google.com. While this CA is not publicly-trusted as a part of the webPKI, its relative ubiquity and demonstrable misuse warrant protecting Chrome users by blocking trust in it.
,
May 22 2018
Friendly ping to get an update on this issue as it is marked as RBB. Thanks..!
,
May 22 2018
I'm still trying to get in touch with Mitel. I'll take the bug as I continue to do that, as it predicates any other action.
,
May 22 2018
,
May 22 2018
Your bug is tagged as Release block Beta and we are branching in 2 days.Please have a fix ASAP.
,
May 22 2018
Needn't block the first beta (though we'd like to get it into an early one) - moving to RBS
,
May 25 2018
As per C#6, assigning to owner.
,
May 29 2018
As the owner ( awhalley@) last visit shown as 18 days ago, could someone from cc'ed dev please take a look into it. Thanks..!
,
May 29 2018
(Visiting from my chromium.org account to reset that flag!) I've contacted a human at Mitel, currently waiting for a response.
,
Jun 11 2018
Friendly ping to get an update on this issue as it is marked as RBS. Thanks..!
,
Jun 15 2018
Thanks for the ping. Change is up for review, but at this point it's probably best to just slip to 69.
,
Jun 19 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/211c7979fe5bcef296ca35dfa85a5aa82f65a25c commit 211c7979fe5bcef296ca35dfa85a5aa82f65a25c Author: Andrew R. Whalley <awhalley@google.com> Date: Tue Jun 19 05:12:18 2018 Blacklist potentially compromised Mitel keys See https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-17-0001 Bug= 844069 Change-Id: I0c7597689981279b3a260f4c3c7d681529b22a01 Reviewed-on: https://chromium-review.googlesource.com/1103224 Commit-Queue: Andrew Whalley <awhalley@google.com> Reviewed-by: Ryan Sleevi <rsleevi@chromium.org> Cr-Commit-Position: refs/heads/master@{#568348} [modify] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/cert/cert_verify_proc_blacklist.inc [add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/2a33f5b48176523fd3c0d854f20093417175bfd498ef354cc7f38b54adabaf1a.pem [add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/2d11e736f0427fd6ba4b372755d34a0edd8d83f7e9e7f6c01b388c9b7afa850d.pem [add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/3ab0fcc7287454c405863e3aa204fea8eb0c50a524d2a7e15524a830cd4ab0fe.pem [add] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/60911c79835c3739432d08c45df64311e06985c5889dc5420ce3d142c8c7ef58.pem [modify] https://crrev.com/211c7979fe5bcef296ca35dfa85a5aa82f65a25c/net/data/ssl/blacklist/README.md
,
Jun 19 2018
,
Jul 10
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/de70fd58d3349f15fb7c6dfb9589029643d3d6c3 commit de70fd58d3349f15fb7c6dfb9589029643d3d6c3 Author: Emily Stark <estark@google.com> Date: Tue Jul 10 23:13:00 2018 Show MITM interstitial for blocked compromised Mitel keys These keys have been blacklisted in https://chromium-review.googlesource.com/1103224. We can use dynamic interstitials to trigger the special MITM interstitial for them. This interstitial can be seen at chrome://interstitials/mitm-software-ssl. It informs the user that there is misconfigured software and that they should contact their network administrator. Bug: 844069 Cq-Include-Trybots: luci.chromium.try:closure_compilation Change-Id: I21a5257f48e88347792e9e5c9ed0d45cfa7f4ee2 Reviewed-on: https://chromium-review.googlesource.com/1132379 Reviewed-by: Mustafa Emre Acer <meacer@chromium.org> Commit-Queue: Emily Stark <estark@chromium.org> Cr-Commit-Position: refs/heads/master@{#573969} [modify] https://crrev.com/de70fd58d3349f15fb7c6dfb9589029643d3d6c3/chrome/browser/resources/ssl/ssl_error_assistant/ssl_error_assistant.asciipb |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by awhalley@google.com
, May 17 2018