Add Trust Anchor IDs support to TlsStreamAttempt/HttpStreamPool This CL adds support for TLS Trust Anchor IDs (https://tlswg.org/tls-trust-anchor-ids/draft-ietf-tls-trust-anchor-ids.html) to the new Happy Eyeballs v3 code path for creating SSLClientSockets. Initial Trust Anchor IDs (formed from the intersection of the Trust Anchor IDs that Chrome trusts with those the server advertises in DNS) are configured on the connection in HttpStreamPool::AttemptManager. If TlsStreamAttempt fails with a certificate error and the server has provided up-to-date Trust Anchor IDs in the handshake, then TlsStreamAttempt retries itself, using the intersection with the new Trust Anchor IDs provided by the server. This CL is the HEv3 equivalent of https://chromium-review.googlesource.com/c/chromium/src/+/6578737 and https://chromium-review.googlesource.com/c/chromium/src/+/6627510. Bug: 424256394 Change-Id: Iea3f29036035024b28808588d7819daa1beb2066 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6635900 Commit-Queue: Emily Stark <estark@chromium.org> Reviewed-by: Kenichi Ishibashi <bashi@chromium.org> Cr-Commit-Position: refs/heads/main@{#1474668}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure.
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.