Issue metadata
Sign in to add a comment
|
--disable-features=SSLCommonNameMismatchHandling" not working / breaching our security
Reported by
arjuniet...@gmail.com,
Aug 4
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:61.0) Gecko/20100101 Firefox/61.0 Steps to reproduce the problem: Issue 870739 in chromium: CNAME redirection possible to exploit you cant close that issue , its not that simple What is the expected behavior? you gave me a non working solution and closed the issue ? why ? What went wrong? No it didn't worked for me . I launched crome as you guided said with the switch you said ..same situation not blocking even now .. And as you said a technically incorrect statement "IF SSL OF WWW IS PROVIDED SWITCHING BETWEEN WWW<----> NON WWW WILL BE SEEN cname redirect will not be followeed . As per my understanding browser will first lookup dns ..got redirected by CNAME and the the tls handhake begins and SAN will be looked for domain in request and that is the CNAME redirected one We are facing a potential secrurity issue owing to it ...plz get it resolved Did this work before? N/A Chrome version: <Copy from: 'about:version'> Channel: n/a OS Version: OS X 10.12 Flash Version: Issue 870739 in chromium: CNAME redirection possible to exploit you gave me a non working solution and closed the issue ? why ?
,
Nov 13
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Aug 6Status: Duplicate (was: Unconfirmed)