Closed Bug 1675655 Opened 1 year ago Closed 2 months ago

measure when CRLite and OCSP fetching differ


(Core :: Security: PSM, enhancement, P1)




94 Branch
Tracking Status
firefox94 --- fixed


(Reporter: jcj, Assigned: keeler)


(Blocks 1 open bug)


(Whiteboard: [psm-assigned])


(2 files)

This is to-be-discussed in Monday's meeting, but:

We had on our list the idea of comparing OCSP results against CRLite results and evaluating that telemetry before proceeding to Beta testing.

The problem is, revocations are rare events, almost unto statistical anomalies, so I'm a little concerned as to whether we'll have enough possibility of signal to justify the effort here, compared to just enabling Enforce mode and waiting for bug reports.

Anyway, discuss Monday, and here's the bug should we need it.

(as this is an enhancement, its severity should be n/a)

Assignee: nobody → dkeeler
Severity: -- → N/A
Priority: -- → P1
Summary: Add a CRLite mode to compare with OCSP and emit telemetry → measure when CRLite and OCSP fetching differ
Whiteboard: [psm-assigned]

The added telemetry category labels are cryptically short because there is a
limit of 20 characters for each one.

Attached file
Attachment #9242137 - Flags: data-review?(chutten)

Comment on attachment 9242137 [details]


Is there or will there be documentation that describes the schema for the ultimate data set available publicly, complete and accurate?


Is there a control mechanism that allows the user to turn the data collection on and off?

Yes. This collection is Telemetry so can be controlled through Firefox's Preferences.

If the request is for permanent data collection, is there someone who will monitor the data over time?

No. This collection will expire in six months.

Using the category system of data types on the Mozilla wiki, what collection type of data do the requested measurements fall under?

Category 2, Interaction.

Is the data collection request for default-on or default-off?

Default on for all channels.

Does the instrumentation include the addition of any new identifiers?


Is the data collection covered by the existing Firefox privacy notice?


Does the data collection use a third-party collection tool?


Result: datareview+

Attachment #9242137 - Flags: data-review?(chutten) → data-review+
Attachment #9241221 - Attachment description: Bug 1675655 - gather telemetry on how often CRLite and OCSP disagree r?rmf!,jschanck! → Bug 1675655 - gather telemetry on how often CRLite and OCSP disagree data-review=chutten r?jschanck!
Pushed by
gather telemetry on how often CRLite and OCSP disagree data-review=chutten r=jschanck
Closed: 2 months ago
Resolution: --- → FIXED
Target Milestone: --- → 94 Branch
You need to log in before you can comment on or make changes to this bug.