mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-10-04 06:17:30 +09:00
Issue #1280 - Follow-up: Get rid of HPKP pinning mode.
This was a leftover from HPKP removal. Also remove a couple of unused variables from security/manager/ssl/nsSiteSecurityService.cpp.
This commit is contained in:
parent
e31680357e
commit
2924d30a83
7 changed files with 14 additions and 42 deletions
|
|
@ -20,12 +20,12 @@ public:
|
|||
|
||||
SharedCertVerifier(OcspDownloadConfig odc, OcspStrictConfig osc,
|
||||
OcspGetConfig ogc, uint32_t certShortLifetimeInDays,
|
||||
PinningMode pinningMode, SHA1Mode sha1Mode,
|
||||
SHA1Mode sha1Mode,
|
||||
BRNameMatchingPolicy::Mode nameMatchingMode,
|
||||
NetscapeStepUpPolicy netscapeStepUpPolicy,
|
||||
CertificateTransparencyMode ctMode)
|
||||
: mozilla::psm::CertVerifier(odc, osc, ogc, certShortLifetimeInDays,
|
||||
pinningMode, sha1Mode, nameMatchingMode,
|
||||
sha1Mode, nameMatchingMode,
|
||||
netscapeStepUpPolicy, ctMode)
|
||||
{
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1579,14 +1579,6 @@ void nsNSSComponent::setValidationOptions(bool isInitialSetting,
|
|||
PublicSSLState()->SetSignedCertTimestampsEnabled(sctsEnabled);
|
||||
PrivateSSLState()->SetSignedCertTimestampsEnabled(sctsEnabled);
|
||||
|
||||
CertVerifier::PinningMode pinningMode =
|
||||
static_cast<CertVerifier::PinningMode>
|
||||
(Preferences::GetInt("security.cert_pinning.enforcement_level",
|
||||
CertVerifier::pinningDisabled));
|
||||
if (pinningMode > CertVerifier::pinningEnforceTestMode) {
|
||||
pinningMode = CertVerifier::pinningDisabled;
|
||||
}
|
||||
|
||||
CertVerifier::SHA1Mode sha1Mode = static_cast<CertVerifier::SHA1Mode>
|
||||
(Preferences::GetInt("security.pki.sha1_enforcement_level",
|
||||
static_cast<int32_t>(CertVerifier::SHA1Mode::Allowed)));
|
||||
|
|
@ -1646,7 +1638,7 @@ void nsNSSComponent::setValidationOptions(bool isInitialSetting,
|
|||
lock);
|
||||
mDefaultCertVerifier = new SharedCertVerifier(odc, osc, ogc,
|
||||
certShortLifetimeInDays,
|
||||
pinningMode, sha1Mode,
|
||||
sha1Mode,
|
||||
nameMatchingMode,
|
||||
netscapeStepUpPolicy,
|
||||
ctMode);
|
||||
|
|
|
|||
|
|
@ -87,8 +87,6 @@ SiteHSTSState::ToString(nsCString& aString)
|
|||
|
||||
////////////////////////////////////////////////////////////////////////////////
|
||||
|
||||
const uint64_t kSixtyDaysInSeconds = 60 * 24 * 60 * 60;
|
||||
|
||||
static bool
|
||||
HostIsIPAddress(const char *hostname)
|
||||
{
|
||||
|
|
@ -398,8 +396,6 @@ ParseSSSHeaders(uint32_t aType,
|
|||
// Unrecognized directives (that are otherwise syntactically valid) are
|
||||
// ignored, and the rest of the header is parsed as normal.
|
||||
|
||||
bool foundReportURI = false;
|
||||
|
||||
NS_NAMED_LITERAL_CSTRING(max_age_var, "max-age");
|
||||
NS_NAMED_LITERAL_CSTRING(include_subd_var, "includesubdomains");
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue