Commit graph

72 commits

Author SHA1 Message Date
Matt A. Tobin
97059c1b48 Issue #1053 - Drop support Android and remove Fennec - Part 1b: Remove MOZ_FENNEC 2019-04-27 08:51:55 +08:00
adeshkp
6a0abd1cd5 Remove SecurityUI telemetry. 2019-04-27 08:23:50 +08:00
adeshkp
5193311ea5 Fix order of member variables in a couple of initializer lists 2019-03-16 07:04:11 +08:00
trav90
7c9325064a Update HSTS preload list
Tag #447
2019-02-16 00:27:43 +08:00
Ascrod
b85fb498d9 Fix check for HSTS when service is disabled. 2019-02-16 00:24:25 +08:00
Ascrod
57ca286478 Add preference for fully disabling HSTS. 2019-02-16 00:24:23 +08:00
adeshkp
813140d8c7 Remove a pointless switch after telemetry cleanup 2019-02-16 00:24:07 +08:00
adeshkp
aea50f182f Telemetry: Remove stubs and related code 2019-02-16 00:24:04 +08:00
trav90
651f0bfce6 Update HSTS preload list
Tag #447
2019-02-16 00:23:51 +08:00
trav90
cad597caf0 Update HSTS preload list
Tag #447
2019-02-16 00:22:33 +08:00
wolfbeast
5f0986e66f Update NSS to 3.41 2019-02-16 00:22:24 +08:00
trav90
fa5aa7b3d8 Update HSTS preload list
Tag #447
2019-02-16 00:20:30 +08:00
wolfbeast
d8ccdaa0d9 Remove AccumulateCipherSuite()
This resolves #858
2019-02-16 00:19:07 +08:00
wolfbeast
64a8472788 Remove ancient workaround in client certificate code
Apparently a prehistoric server implementation would send a certificate_authorities field
that didn't include the outer DER SEQUENCE tag, so PSM attempted to detect this and
work around it.
This prehistoric server implementation isn't in use anywhere anymore, so this 18-yo
server bug workaround can be removed.
2019-02-16 00:18:40 +08:00
wolfbeast
6c4b9ec3ce Make sure nsNSSCertList handling checks for valid certs. 2019-02-16 00:18:31 +08:00
trav90
37fe93abff Update HSTS preload list
Tag #447
2019-02-16 00:18:13 +08:00
trav90
2bce502df7 Update HSTS preload list
Tag #447
2019-02-16 00:15:49 +08:00
wolfbeast
55c45dc7f2 Ensure we got an nsISSLStatus when deserializing in TransportSecurityInfo. 2019-02-16 00:15:09 +08:00
trav90
c576139ef2 Update HSTS preload list
Tag #447
2019-02-16 00:14:42 +08:00
wolfbeast
bd525435bf Get rid of the incorrect mechanism to remove insecure fallback hosts.
This fixes #797.
2019-02-16 00:14:39 +08:00
trav90
4f41aebb67 Update HSTS preload list
Tag #447
2019-02-16 00:13:42 +08:00
wolfbeast
8c8145e620 Remove all C++ Telemetry Accumulation calls.
This creates a number of stubs and leaves some surrounding code that may be irrelevant (eg. recorded time stamps, status variables).
Stub resolution/removal should be a follow-up to this.
2019-02-16 00:12:32 +08:00
wolfbeast
e2e197cada Remove support for TLS session caches in TLSServerSocket.
This resolves #738
2019-02-16 00:12:22 +08:00
trav90
450c242d9f Update HSTS preload list
Tag #447
2019-02-16 00:12:12 +08:00
wolfbeast
4debc9246e Fix missed in32->int64 in df852120098dc7ba5df4a76126c6297c6d2d1b7b
Tag #709.
2019-02-16 00:11:26 +08:00
wolfbeast
8effb3030e Reinstate RC4 and mark 3DES weak.
Tag #709
2019-02-16 00:11:24 +08:00
wolfbeast
7f72783c00 Extend {EnabledWeakCiphers} bit field to allow more cipher suites.
Tag #709.
2019-02-16 00:11:23 +08:00
wolfbeast
d36d4eb674 Update NSS to 3.38
- Added HACL*Poly1305 32-bit (INRIA/Microsoft)
- Updated to final TLS 1.3 draft version (28)
- Removed TLS 1.3 prerelease draft limit check
- Removed NPN code
- Enabled dev/urandom-only RNG on Linux with NSS_SEED_ONLY_DEV_URANDOM for non-standard environments
- Fixed several bugs with TLS 1.3 negotiation
- Updated internal certificate store
- Added support for the TLS Record Size Limit Extension.
- Fixed CVE-2018-0495
- Various security fixes in the ASN.1 code.
2019-02-16 00:11:10 +08:00
trav90
b266e5e349 Update HSTS preload list
Tag #447
2019-02-16 00:10:17 +08:00
yami
4470fb65f3 replace "certErrorCodePrefix2" with "certErrorCodePrefix" 2019-02-16 00:09:37 +08:00
wolfbeast
93c640e3b1 Remove incorrect debug assertion.
solves #631, solves #664
2019-02-16 00:09:29 +08:00
trav90
d8992204e1 Update HSTS preload list
Tag #447
2019-02-16 00:08:57 +08:00
wolfbeast
1ed60ee41b Don't leak newTemplate in pk11_copyAttributes()
Cherry-pick of NSS fix from 3.37
2019-02-16 00:07:15 +08:00
wolfbeast
7b82a2ece4 Remove SSL Error Reporting telemetry 2019-02-16 00:06:16 +08:00
trav90
a179019413 Update HSTS preload list
Tag #447
2019-02-16 00:03:49 +08:00
wolfbeast
624aa2c581 Fix SSL status ambiguity.
- Adds CipherSuite string with the full suite
- Changes CipherName to be the actual cipher name instead of the (erroneous) full suite like Firefox does.
2019-02-16 00:03:48 +08:00
JustOff
fe96962962 Update NSS to 3.36.4-RTM 2019-02-16 00:02:32 +08:00
JustOff
f9dfa17007 [PALEMOON] Add missed strings required by page info 2019-02-16 00:02:09 +08:00
trav90
0c4e5ff00d Regenerate the HSTS preload list 2019-02-16 00:01:48 +08:00
trav90
70b28bf2ee Restore clearly-delimited format for the HSTS preload list 2019-02-16 00:01:46 +08:00
trav90
e8d7388622 Increase concurrent lookups to 15 when generating HSTS preload list 2019-02-16 00:01:45 +08:00
trav90
4752033ff0 Update HSTS preload list generation script
Previous behavior: if an entry was in the previously-used list, and there would be an error connecting to or processing the host, it would adopt it using the previous status, with a new minimum required max age TTL.
New behavior: if an entry is in the previously-used list, and there is an error connecting to or processing the host, it will be dropped from the preload list.

The old behavior would allow entries to persist on the HSTS preload list when they drop off the 'net. Considering domain churn, it would cause issues for new owners for having a persisted HSTS entry preloaded in the browser.
Bonus: it keeps our HSTS preload list lean.
2019-02-16 00:01:43 +08:00
JustOff
7ff80ee648 Request NSS to use DBM as the storage file format 2019-02-16 00:01:09 +08:00
wolfbeast
8c296a9714 Revert "Restore NSS default storage file format to DBM when no prefix is given."
This reverts commit b2c78bbf83f75bf034028814329fdd43b6bfe885.
2019-02-16 00:01:08 +08:00
wolfbeast
e88fd14de6 Restore NSS default storage file format to DBM when no prefix is given. 2019-02-16 00:01:06 +08:00
wolfbeast
608f9fca02 Update NSS to 3.35-RTM 2019-02-16 00:01:03 +08:00
Gaming4JC
d4ac94cf3e Remove support and tests for HSTS priming from the tree. Fixes #384 2019-02-15 23:59:39 +08:00
wolfbeast
b586913598 Remove MOZ_WIDGET_GONK [1/2]
Tag #288
2019-02-15 23:57:08 +08:00
wolfbeast
a0decb1dcc Nuke the sandbox 2019-02-15 23:55:43 +08:00
wolfbeast
c8462db202 Remove sandbox ductwork conditional code. 2019-02-15 23:55:41 +08:00