Hi Tomorrow,

Please refer to https://crosswalk-project.org/jira/browse/XWALK-7429 for “will 
not reach XWalkResourceClient::onReceivedSslError” issue.

If you remove ERR_CERT_AUTHORITY_INVALID from denied list, it will cause 
vulnerability issue described in: 
https://lists.crosswalk-project.org/pipermail/crosswalk-help/2016-July/002167.html

BR
Belem

From: Crosswalk-dev [mailto:[email protected]] 
On Behalf Of tomorrow chen
Sent: Tuesday, November 15, 2016 6:44 PM
To: [email protected]
Subject: [Crosswalk-dev] why deny ERR_CERT_AUTHORITY_INVALID SSL error

Hi All
I'm using crosswalk22.
I found the ssl error ERR_CERT_AUTHORITY_INVALID will be denied by 
XWalkContentsBridge and will not reach XWalkResourceClient::onReceivedSslError.
I read 
https://github.com/crosswalk-project/chromium-crosswalk/blob/master/content/browser/ssl/ssl_policy.cc#L61
 ,but still failed to got the reason.
Why should it be decided by client?
Is there any side effect if I remove it from denied list?
_______________________________________________
Crosswalk-help mailing list
[email protected]
https://lists.crosswalk-project.org/mailman/listinfo/crosswalk-help

Reply via email to