[SCT Auditing] Only audit SCTs for certs issued from known roots
This is an initial solution for crbug.com/1129197 -- the full solution is implemented in crrev.com/c/2422435 but requires changes to allow mocking CT results in order to land. This prevents logging private certificates, and adds a test explicitly exercising this case. It also makes the browser tests a bit more robust by tracking the last report seen by the test server and adding a step to flush a new report through for negative tests. Bug: 1129197 Change-Id: I7e1d4010b2666db7f98194aa1e3ba80df1e0a493 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2453777Reviewed-by:Emily Stark <estark@chromium.org> Reviewed-by:
David Schinazi <dschinazi@chromium.org> Reviewed-by:
Nick Harper <nharper@chromium.org> Reviewed-by:
Kinuko Yasuda <kinuko@chromium.org> Commit-Queue: Kinuko Yasuda <kinuko@chromium.org> Auto-Submit: Chris Thompson <cthomp@chromium.org> Cr-Commit-Position: refs/heads/master@{#815086}
Showing
This diff is collapsed.
Please register or sign in to comment