Closed Bug 1142769 Opened 10 years ago Closed 10 years ago

Fallback whitelist update: late-March 2015

Categories

(Core :: Security: PSM, defect)

37 Branch
defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla39
Tracking Status
firefox37 + fixed
firefox38 + fixed
firefox39 + fixed

People

(Reporter: emk, Assigned: emk)

References

Details

Attachments

(1 file, 2 obsolete files)

+++ This bug was initially created as a clone of Bug #1133187 +++ I would like to land this before the next merge.
[Tracking Requested - why for this release]:
Ah, this is also needed for the version fallback.
OK, sounds like we should track (and probably uplift) whatever ends up on this whitelist all the way to beta (37).
Hi emk, the last 37 Beta goes to build this Thu, Mar 19 if you are still looking to land a new whitelist and request uplift to 37.
Flags: needinfo?(VYV03354)
Attached patch update_whitelist (obsolete) — Splinter Review
* Added sites from bug 1126620 blockers and bug 1138101 blockers. * Added sites from bug 1126620 comment #12. * Removed fixed sites. * Removed following sites (please double check). https://adman.you.gr (certificate expired) https://startrekonline.com (certificate expired) https://webctmt.lau.edu.lb (consistently fails to connect) https://www.3zai.com (unknown host) https://www.bookstore.ccbcmd.edu (unknown host) https://www.emihub.com (certificate expired) https://www.expohotelbarcelona.com (consistently fails to connect) https://www.htsec.com (consistently fails to connect) https://www.oxendales.co.uk (consistently fails to connect) https://www.startrekonline.com (certificate expired)
Flags: needinfo?(VYV03354)
Attachment #8579371 - Flags: review?(dkeeler)
(In reply to Masatoshi Kimura [:emk] from comment #5) > * Removed following sites (please double check). > https://adman.you.gr (certificate expired) > https://startrekonline.com (certificate expired) > https://webctmt.lau.edu.lb (consistently fails to connect) > https://www.3zai.com (unknown host) > https://www.bookstore.ccbcmd.edu (unknown host) > https://www.emihub.com (certificate expired) > https://www.expohotelbarcelona.com (consistently fails to connect) > https://www.htsec.com (consistently fails to connect) > https://www.oxendales.co.uk (consistently fails to connect) > https://www.startrekonline.com (certificate expired) Same results here, except https://www.bookstore.ccbcmd.edu seems to be reachable via Fx38, IE11 and SSL Labs (although it just redirects to HTTP). Also, I assume omitting the entries from the lists in Bug 1124039 comment 58 and Bug 1138101 comment 4 is intentional since 37 only needs to concern itself with TLS intolerance?
(In reply to Cykesiopka from comment #6) > Also, I assume omitting the entries from the lists in Bug 1124039 comment 58 > and Bug 1138101 comment 4 is intentional since 37 only needs to concern > itself with TLS intolerance? Yes, and also 38 after bug 1138882 uplift with the pref default-enabled.
(In reply to Cykesiopka from comment #6) > Same results here, except https://www.bookstore.ccbcmd.edu seems to be > reachable via Fx38, IE11 and SSL Labs (although it just redirects to HTTP). Oh, indeed Google Public DNS found www.bookstore.ccbcmd.edu while my local DNS server didn't.
Attached patch update_whitelist (obsolete) — Splinter Review
* Added back www.bookstore.ccbcmd.edu. * Added cardupgrade.citi.com (from bug 1144726)
Attachment #8579371 - Attachment is obsolete: true
Attachment #8579371 - Flags: review?(dkeeler)
Attachment #8579424 - Flags: review?(dkeeler)
Assignee: nobody → VYV03354
37 Beta 7 goes to build tomorrow (Thu, Mar 19). We need and r+ and an uplift request by tomorrow morning in order to ship this update in 37.
Flags: needinfo?(dkeeler)
Flags: needinfo?(VYV03354)
Comment on attachment 8579424 [details] [diff] [review] update_whitelist Review of attachment 8579424 [details] [diff] [review]: ----------------------------------------------------------------- LGTM with comment addressed. ::: security/manager/ssl/src/IntolerantFallbackList.inc @@ -20,2 @@ > "ad401k.sbisec.co.jp", > - "adman.you.gr", I don't think we should remove any sites where the only problem is an expired certificate. Users will be expecting to be able to still reach those sites by adding exceptions, and I imagine administrators are likely to renew the certificates without changing the cipher prefs.
Attachment #8579424 - Flags: review?(dkeeler) → review+
Flags: needinfo?(dkeeler)
Attached patch patch for chekinSplinter Review
* Restored certificate expired sites. * Added watch.sportsnet.ca (bug 1144769).
Attachment #8579424 - Attachment is obsolete: true
Flags: needinfo?(VYV03354)
Attachment #8579658 - Flags: review+
Currently inbound is closed
Keywords: checkin-needed
Comment on attachment 8579658 [details] [diff] [review] patch for chekin Approval Request Comment [Feature/regressing bug #]: N/A [User impact if declined]: Users can not connect some sites. [Describe test coverage new/current, TreeHerder]: tested locally [Risks and why]: Very low. Only trivial changes to static data. [String/UUID change made/needed]: none
Attachment #8579658 - Flags: approval-mozilla-beta?
Attachment #8579658 - Flags: approval-mozilla-aurora?
Comment on attachment 8579658 [details] [diff] [review] patch for chekin This is a planned update to the whitelist before release. Beta+ Aurora+
Attachment #8579658 - Flags: approval-mozilla-beta?
Attachment #8579658 - Flags: approval-mozilla-beta+
Attachment #8579658 - Flags: approval-mozilla-aurora?
Attachment #8579658 - Flags: approval-mozilla-aurora+
This landed with the wrong bug number, FWIW. Try to be more careful in the future. https://hg.mozilla.org/releases/mozilla-beta/rev/02b9c74353ad
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Blocks: 1145844
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: