summaryrefslogtreecommitdiffstats
path: root/security/manager/ssl/nsNSSComponent.cpp
diff options
context:
space:
mode:
authoradesh <adeshk@hotmail.com>2020-11-10 04:22:12 -0500
committeradesh <adeshk@hotmail.com>2020-11-10 23:07:22 -0500
commit5ef801fdc5744daf9455fc6dcf90d3f7c60ae084 (patch)
tree75f97c59a685652a7b06e3d7ae00757affcfbb8d /security/manager/ssl/nsNSSComponent.cpp
parent0ba1d49ae5564a9e0b141b656a8cdc68e7582baf (diff)
downloadUXP-5ef801fdc5744daf9455fc6dcf90d3f7c60ae084.tar
UXP-5ef801fdc5744daf9455fc6dcf90d3f7c60ae084.tar.gz
UXP-5ef801fdc5744daf9455fc6dcf90d3f7c60ae084.tar.lz
UXP-5ef801fdc5744daf9455fc6dcf90d3f7c60ae084.tar.xz
UXP-5ef801fdc5744daf9455fc6dcf90d3f7c60ae084.zip
Issue #1280 - Follow-up: Get rid of HPKP pinning mode.
This was a leftover from HPKP removal. Also remove a couple of unused variables from security/manager/ssl/nsSiteSecurityService.cpp.
Diffstat (limited to 'security/manager/ssl/nsNSSComponent.cpp')
-rw-r--r--security/manager/ssl/nsNSSComponent.cpp10
1 files changed, 1 insertions, 9 deletions
diff --git a/security/manager/ssl/nsNSSComponent.cpp b/security/manager/ssl/nsNSSComponent.cpp
index 897b5743c..6e6d61441 100644
--- a/security/manager/ssl/nsNSSComponent.cpp
+++ b/security/manager/ssl/nsNSSComponent.cpp
@@ -1579,14 +1579,6 @@ void nsNSSComponent::setValidationOptions(bool isInitialSetting,
PublicSSLState()->SetSignedCertTimestampsEnabled(sctsEnabled);
PrivateSSLState()->SetSignedCertTimestampsEnabled(sctsEnabled);
- CertVerifier::PinningMode pinningMode =
- static_cast<CertVerifier::PinningMode>
- (Preferences::GetInt("security.cert_pinning.enforcement_level",
- CertVerifier::pinningDisabled));
- if (pinningMode > CertVerifier::pinningEnforceTestMode) {
- pinningMode = CertVerifier::pinningDisabled;
- }
-
CertVerifier::SHA1Mode sha1Mode = static_cast<CertVerifier::SHA1Mode>
(Preferences::GetInt("security.pki.sha1_enforcement_level",
static_cast<int32_t>(CertVerifier::SHA1Mode::Allowed)));
@@ -1646,7 +1638,7 @@ void nsNSSComponent::setValidationOptions(bool isInitialSetting,
lock);
mDefaultCertVerifier = new SharedCertVerifier(odc, osc, ogc,
certShortLifetimeInDays,
- pinningMode, sha1Mode,
+ sha1Mode,
nameMatchingMode,
netscapeStepUpPolicy,
ctMode);