diff options
author | Kenny Root <kroot@google.com> | 2015-06-15 12:09:51 -0700 |
---|---|---|
committer | Kenny Root <kroot@google.com> | 2015-06-15 12:35:18 -0700 |
commit | 22de72d26e2a9a526e2c25c56049110a4e584349 (patch) | |
tree | 99b06f51cf5eeaeec9904514dfb885f6cb1d8198 /support/src | |
parent | 9d835973b665a7bcf4601358b44fe2c4a3b833c2 (diff) | |
download | libcore-22de72d26e2a9a526e2c25c56049110a4e584349.zip libcore-22de72d26e2a9a526e2c25c56049110a4e584349.tar.gz libcore-22de72d26e2a9a526e2c25c56049110a4e584349.tar.bz2 |
Do not blacklist serial numbers that are too short
Baseline Requirements say the serial number must have 20-bits of
entropy, but some certificates are issued not in compliance. This causes
issues where they are falsely marked as blacklisted. Until there is
issuer + serial number matching, we can just use the pubkey matching for
the certificates that are blacklisted with non-compliant serial numbers.
Bug: 21736046
Bug: 21816853
Change-Id: I44e6d490099fbe1da2f5afb5ef61196a4593e04f
Diffstat (limited to 'support/src')
0 files changed, 0 insertions, 0 deletions