Make sure HPKP preload expiration date is accurate for 57

RESOLVED FIXED

Status

()

Core
Security: PSM
P2
normal
RESOLVED FIXED
8 months ago
6 months ago

People

(Reporter: RyanVM, Assigned: jcristau)

Tracking

57 Branch
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(firefox57blocking fixed)

Details

(Whiteboard: [psm-blocked] )

Attachments

(1 attachment)

(Reporter)

Description

8 months ago
Confirm and patch security/manager/ssl/StaticHPKPins.h and security/manager/ssl/nsSTSPreloadList.inc in 57 to have sufficient lifetime on the preloaded HPKP and STS pins.

Going off past precedents, I assume we're going to want an expiration date of around 2018-03-06 to coincide with the release of Fx59.
(Assignee)

Updated

8 months ago
tracking-firefox57: ? → blocking
(Assignee)

Comment 1

8 months ago
AIUI this can only land after October 24.
(Assignee)

Updated

6 months ago
Assignee: nobody → jcristau
(Assignee)

Comment 2

6 months ago
Created attachment 8920999 [details] [diff] [review]
hpkp-57.patch
Attachment #8920999 - Flags: review?(dkeeler)
Comment on attachment 8920999 [details] [diff] [review]
hpkp-57.patch

Review of attachment 8920999 [details] [diff] [review]:
-----------------------------------------------------------------

Thanks!
Attachment #8920999 - Flags: review?(dkeeler) → review+
(Assignee)

Comment 4

6 months ago
Comment on attachment 8920999 [details] [diff] [review]
hpkp-57.patch

Approval Request Comment
[Feature/Bug causing the regression]: n/a
[User impact if declined]: builtin key pins would expire on December 27, and hsts preload on January 24
[Is this code covered by automated tests?]: yes
[Has the fix been verified in Nightly?]: n/a, beta-only patch
[Needs manual test from QE? If yes, steps to reproduce]: no
[List of other uplifts needed for the feature/fix]: none
[Is the change risky?]: no
[Why is the change risky/not risky?]: just bumping expiration dates
[String changes made/needed]: none
Attachment #8920999 - Flags: approval-mozilla-beta?
(Assignee)

Updated

6 months ago
Flags: needinfo?(rkothari)

Comment 5

6 months ago
Comment on attachment 8920999 [details] [diff] [review]
hpkp-57.patch

Must fix, Beta57+
Flags: needinfo?(rkothari)
Attachment #8920999 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
(Reporter)

Updated

6 months ago
Status: NEW → RESOLVED
Last Resolved: 6 months ago
Resolution: --- → FIXED
(Reporter)

Comment 6

6 months ago
bugherderuplift
https://hg.mozilla.org/releases/mozilla-beta/rev/9d9ed1a5d9e9
status-firefox57: affected → fixed
(Reporter)

Updated

6 months ago
Blocks: 1412331
You need to log in before you can comment on or make changes to this bug.