trav90
7c9325064a
Update HSTS preload list
...
Tag #447
2019-02-16 00:27:43 +08:00
Ascrod
b85fb498d9
Fix check for HSTS when service is disabled.
2019-02-16 00:24:25 +08:00
Ascrod
57ca286478
Add preference for fully disabling HSTS.
2019-02-16 00:24:23 +08:00
adeshkp
813140d8c7
Remove a pointless switch after telemetry cleanup
2019-02-16 00:24:07 +08:00
adeshkp
aea50f182f
Telemetry: Remove stubs and related code
2019-02-16 00:24:04 +08:00
trav90
651f0bfce6
Update HSTS preload list
...
Tag #447
2019-02-16 00:23:51 +08:00
trav90
cad597caf0
Update HSTS preload list
...
Tag #447
2019-02-16 00:22:33 +08:00
trav90
fa5aa7b3d8
Update HSTS preload list
...
Tag #447
2019-02-16 00:20:30 +08:00
wolfbeast
d8ccdaa0d9
Remove AccumulateCipherSuite()
...
This resolves #858
2019-02-16 00:19:07 +08:00
wolfbeast
64a8472788
Remove ancient workaround in client certificate code
...
Apparently a prehistoric server implementation would send a certificate_authorities field
that didn't include the outer DER SEQUENCE tag, so PSM attempted to detect this and
work around it.
This prehistoric server implementation isn't in use anywhere anymore, so this 18-yo
server bug workaround can be removed.
2019-02-16 00:18:40 +08:00
wolfbeast
6c4b9ec3ce
Make sure nsNSSCertList handling checks for valid certs.
2019-02-16 00:18:31 +08:00
trav90
37fe93abff
Update HSTS preload list
...
Tag #447
2019-02-16 00:18:13 +08:00
trav90
2bce502df7
Update HSTS preload list
...
Tag #447
2019-02-16 00:15:49 +08:00
wolfbeast
55c45dc7f2
Ensure we got an nsISSLStatus when deserializing in TransportSecurityInfo.
2019-02-16 00:15:09 +08:00
trav90
c576139ef2
Update HSTS preload list
...
Tag #447
2019-02-16 00:14:42 +08:00
wolfbeast
bd525435bf
Get rid of the incorrect mechanism to remove insecure fallback hosts.
...
This fixes #797 .
2019-02-16 00:14:39 +08:00
trav90
4f41aebb67
Update HSTS preload list
...
Tag #447
2019-02-16 00:13:42 +08:00
wolfbeast
8c8145e620
Remove all C++ Telemetry Accumulation calls.
...
This creates a number of stubs and leaves some surrounding code that may be irrelevant (eg. recorded time stamps, status variables).
Stub resolution/removal should be a follow-up to this.
2019-02-16 00:12:32 +08:00
wolfbeast
e2e197cada
Remove support for TLS session caches in TLSServerSocket.
...
This resolves #738
2019-02-16 00:12:22 +08:00
trav90
450c242d9f
Update HSTS preload list
...
Tag #447
2019-02-16 00:12:12 +08:00
wolfbeast
4debc9246e
Fix missed in32->int64 in df852120098dc7ba5df4a76126c6297c6d2d1b7b
...
Tag #709 .
2019-02-16 00:11:26 +08:00
wolfbeast
8effb3030e
Reinstate RC4 and mark 3DES weak.
...
Tag #709
2019-02-16 00:11:24 +08:00
wolfbeast
7f72783c00
Extend {EnabledWeakCiphers} bit field to allow more cipher suites.
...
Tag #709 .
2019-02-16 00:11:23 +08:00
trav90
b266e5e349
Update HSTS preload list
...
Tag #447
2019-02-16 00:10:17 +08:00
yami
4470fb65f3
replace "certErrorCodePrefix2" with "certErrorCodePrefix"
2019-02-16 00:09:37 +08:00
trav90
d8992204e1
Update HSTS preload list
...
Tag #447
2019-02-16 00:08:57 +08:00
wolfbeast
7b82a2ece4
Remove SSL Error Reporting telemetry
2019-02-16 00:06:16 +08:00
trav90
a179019413
Update HSTS preload list
...
Tag #447
2019-02-16 00:03:49 +08:00
wolfbeast
624aa2c581
Fix SSL status ambiguity.
...
- Adds CipherSuite string with the full suite
- Changes CipherName to be the actual cipher name instead of the (erroneous) full suite like Firefox does.
2019-02-16 00:03:48 +08:00
JustOff
f9dfa17007
[PALEMOON] Add missed strings required by page info
2019-02-16 00:02:09 +08:00
trav90
0c4e5ff00d
Regenerate the HSTS preload list
2019-02-16 00:01:48 +08:00
trav90
70b28bf2ee
Restore clearly-delimited format for the HSTS preload list
2019-02-16 00:01:46 +08:00
trav90
e8d7388622
Increase concurrent lookups to 15 when generating HSTS preload list
2019-02-16 00:01:45 +08:00
trav90
4752033ff0
Update HSTS preload list generation script
...
Previous behavior: if an entry was in the previously-used list, and there would be an error connecting to or processing the host, it would adopt it using the previous status, with a new minimum required max age TTL.
New behavior: if an entry is in the previously-used list, and there is an error connecting to or processing the host, it will be dropped from the preload list.
The old behavior would allow entries to persist on the HSTS preload list when they drop off the 'net. Considering domain churn, it would cause issues for new owners for having a persisted HSTS entry preloaded in the browser.
Bonus: it keeps our HSTS preload list lean.
2019-02-16 00:01:43 +08:00
JustOff
7ff80ee648
Request NSS to use DBM as the storage file format
2019-02-16 00:01:09 +08:00
Gaming4JC
d4ac94cf3e
Remove support and tests for HSTS priming from the tree. Fixes #384
2019-02-15 23:59:39 +08:00
wolfbeast
b586913598
Remove MOZ_WIDGET_GONK [1/2]
...
Tag #288
2019-02-15 23:57:08 +08:00
janekptacijarabaci
b56d147095
Fix unsafe "instanceof" negations
...
https://github.com/MoonchildProductions/Pale-Moon/pull/1173
2019-02-15 23:55:28 +08:00
janekptacijarabaci
b9ed9af662
moebius#119: (Windows) Security - Certificate Stores - NSSCertDBTrustDomain allows end-entities to be their own trust anchors
...
https://github.com/MoonchildProductions/moebius/pull/119
2019-02-15 23:49:14 +08:00
wolfbeast
b23857f77b
Fix build system translation errors.
...
Follow-up to 11a8a39f6d2e057d51559c52c1bf0ba74bbfe189
2019-02-15 23:35:25 +08:00
janekptacijarabaci
38e95f9e35
DevTools - network - security (improvements)
...
https://github.com/MoonchildProductions/moebius/pull/113
https://github.com/MoonchildProductions/moebius/pull/118
https://github.com/MoonchildProductions/moebius/pull/127
2019-02-15 23:34:38 +08:00
NTD
a25b655d51
Use MOZ_FENNEC and MOZ_XULRUNNER instead of checking MOZ_BUILD_APP in most places
2019-02-15 23:34:16 +08:00
wolfbeast
504e1d12bb
Disable 3DES cipher by default + re-order a few things.
...
Issue #4 point 4
2019-02-14 14:28:30 +08:00
wolfbeast
05d35d3d18
Add RSA-AES + SHA256/384 suites for web compatibility.
...
Sites with these ciphers (commonly IIS) would otherwise fall back to weak 3DES that will be disabled by default.
Issue #4 points 2 and 3
2019-02-14 14:28:29 +08:00
wolfbeast
3ecea693f6
Add Camellia to the active cipher suites.
...
Issue #4 point 1.
Camellia is a strong, modern, safe cipher with no known weaknesses or reduced strength attacks.
The cipher has been approved for use by the ISO/IEC, the European Union's NESSIE project and the Japanese CRYPTREC project.
2019-02-14 14:28:27 +08:00
NTD
f5048f2a1d
Remove kinto client, Firefox kinto storage adapter, blocklist update client and integration with sync, OneCRL and the custom time check for derives system time.
2019-02-14 14:27:06 +08:00
Roy Tam
dcd9973243
import FIREFOX_52_6_0esr_RELEASE from mozilla-esr52 hg repo
2018-01-19 03:59:58 +08:00