Commit Graph

24 Commits

Author SHA1 Message Date
Pale Moon e494ef04df Re-generate HSTS preload list without stale entries.
Tag #62.
2018-07-25 09:20:17 +08:00
trav90 d9de979f3b Update HSTS preload list
Tag #62.
2018-07-25 09:10:49 +08:00
trav90 2a0fefaccb Update HSTS preload list
Tag #62.
2018-07-25 09:03:15 +08:00
trav90 d8017389fe Update HSTS preload list
Tag #62.
2018-07-25 08:09:47 +08:00
trav90 e7b92b5c61 Update HSTS preload list
Tag #62.
2018-07-25 07:57:22 +08:00
trav90 b78ff1e752 Update HSTS preload list
Tag #62.
2018-07-25 07:36:59 +08:00
Pale Moon c60bd2e25e HSTS preload list update.
Also increases the concurrent lookups to 15.
Tag #62.
2018-07-25 07:17:35 +08:00
trav90 c924243e71 Fix -Wreorder GCC warning 2018-07-25 07:16:40 +08:00
Pale Moon dce17a6724 Remove preloading of domain PKPins Part 2
- Remove security.cert_pinning.process_headers_from_non_builtin_roots

Tag #925
2018-07-25 07:11:08 +08:00
Pale Moon 972b14bd7b Remove preloading of domain PKPins Part 1
- Remove static lists
- Remove tools to generate static lists
- Remove no longer used structs

Tag #925
2018-07-25 07:11:06 +08:00
trav90 a3187e5712 Update HSTS preload list
Tag #62.
2018-07-25 07:05:27 +08:00
NTD b3a189d2de Follow up to 7bd7e8a - *aState needs both STATE_IS_SECURE and STATE_SECURE_HIGH on re-eval of mixed content 2018-07-25 06:52:56 +08:00
Pale Moon 3ca7947b8a Reset mixed-mode page status to secure if no actual load has occurred through the mixed content blocker.
This should take care of injection of non-network URIs that aren't same origin (e.g. extension-sourced data: URIs) triggering mixed-mode warnings.
Assumption here is that data: URIs are safe if "local"; this is a security trade-off that should be acceptable.
2018-07-25 06:52:49 +08:00
Pale Moon 3398a810ae Update HSTS preload list.
Tag #62.
2018-07-25 06:51:16 +08:00
trav90 17da3b2364 Update HSTS Preload list 2018-07-25 06:42:57 +08:00
Pale Moon 9739829d2d Don't write HSTS site state to file if HSTS has been user-disabled.
This also adds a missing pref observer.
Follow-up to 9bc65e235b62c4e84c69f301bd89de29769f4abf.
2018-07-25 06:36:48 +08:00
Pale Moon 8bd908fa4b Reinstate network.stricttransportsecurity.enabled HSTS switch.
Defaults to enabled (HSTS on) but can be flipped to disable the use of the HSTS mechanism, trading security for privacy.
This resolves #830.
2018-07-25 06:36:25 +08:00
trav90 e035fc775e Update HSTS preload list 2018-07-25 06:22:07 +08:00
trav90 1ab1dc37b6 Update HSTS preload list 2018-07-25 01:30:01 +08:00
Pale Moon 4b96ad2190 HSTS preload list update.
Tag #62.
2018-07-25 01:18:04 +08:00
Pale Moon b142256756 Update list of known CA root hashes 2018-07-25 01:05:11 +08:00
trav90 afa5e10326 Update HSTS Preload List 2018-07-24 23:39:44 +08:00
wolfbeast 5ee6187aad Prep tree for forward-porting Goanna, stage 1 2018-07-24 23:10:50 +08:00
Moonchild baf46a6bf1 Merge pull request #1 from mozilla/esr38: Esr38 upstream pull 2018-07-24 23:04:07 +08:00