Open Bug 711014 Opened 14 years ago Updated 2 years ago

Defer SSL initialization so that it doesn't occur during startup (during nsNSSComponent::Init)

Categories

(Core :: Security: PSM, enhancement, P3)

enhancement

Tracking

()

People

(Reporter: briansmith, Unassigned)

References

(Depends on 1 open bug, Blocks 1 open bug)

Details

(Keywords: perf, Whiteboard: [ts][psm-backlog])

http://hg.mozilla.org/mozilla-central/annotate/beac16509534/security/manager/ssl/src/nsNSSComponent.cpp#l1753 The following calls can be deferred to the time that the first NSS Socket is configured: ::NSS_SetDomesticPolicy(); SSL_OptionSetDefault(...) SSL_CipherPrefSetDefault(...); For example, these can be deferred to the time where the first SSL socket is configured. My hypothesis is that this will help prevent libssl from being loaded during startup. We may need to make libssl a delay-loaded DLL for this to have maximum positive impact; see bug 553727.
More SSL-related calls that can be deferred: nsSSLIOLayerHelpers::Init(); nsSSLIOLayerHelpers::setRenegoUnrestrictedSites(...); nsSSLIOLayerHelpers::setTreatUnsafeNegotiationAsBroken(enabled); nsSSLIOLayerHelpers::setWarnLevelMissingRFC5746(warnLevel); mClientAuthRememberService = new nsClientAuthRememberService; mClientAuthRememberService->Init();
Whiteboard: [ts] → [ts][psm-backlog]
Priority: -- → P3
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.