Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Create new X509CertificateLoader - #102167

Merged
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader
Jun 25, 2024
Merged

Create new X509CertificateLoader#102167
bartonjs merged 21 commits into
dotnet:mainfrom
bartonjs:x509loader

Conversation

@bartonjs

Copy link
Copy Markdown
Member

The new certificate loader only loads one data type per method, unlike the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also allows for caller configuration to control cost-of-work limits and some common usability gotchas around Windows PFX loading.

This change adds the new loader, and changes the X509Certificate2 ctors to use it; a followup will mark the ctors as Obsolete and update usage in the dotnet/runtime codebase.

Contributes to #91763.

The new certificate loader only loads one data type per method, unlike
the previous loader mechanism (new X509Certiicate2(bytes, ...)). It also
allows for caller configuration to control cost-of-work limits and some
common usability gotchas around Windows PFX loading.
This change adds the new loader, and changes the X509Certificate2 ctors
to use it; a followup will mark the ctors as Obsolete and update usage in
the dotnet/runtime codebase.
@bartonjsbartonjs added this to the 9.0.0 milestone May 13, 2024
@bartonjsbartonjs self-assigned this May 13, 2024
@ghost

Copy link
Copy Markdown

Note regarding the new-api-needs-documentation label:

This serves as a reminder for when your PR is modifying a ref *.cs file and adding/modifying public APIs, please make sure the API implementation in the src *.cs file is documented with triple slash comments, so the PR reviewers can sign off that change.

set
{
if (value < 0)
throw new ArgumentOutOfRangeException(nameof(value), SR.ArgumentOutOfRange_NeedNonNegNum);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Earlier an ifdef was used to use ObjectDisposedException.ThrowIf if it's available. I assume we're not doing so here with AOORE just because there are a bunch of them and it'd be abnoxious?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That was the reason, yeah; but looking at it now in this file it's just repeating a negative check, so making a helper seems reasonable (it'll get re-used)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How "amusing"... I updated every instance except the one this comment was on. Fixed locally now.

{
if (!pfxAsn.VerifyMac(password, authSafeContents))
{
password = password.ContainsNull() ? "".AsSpan() : default;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not clear on the reasoning here. If it contains null we make it non-null and if it doesn't contain null we make it null?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep. From the API perspective null and empty are the same thing, but from the algorithm perspective they're different. So if we got null, try again with empty, and if we got empty, try again with null.

@vcsjonesvcsjones left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What I have so far. Scrollbar says I have a ways to go still.

Comment threadsrc/libraries/Common/src/System/Security/Cryptography/Helpers.cs Outdated
Comment threadsrc/libraries/Microsoft.Bcl.Cryptography/tests/X509Certificates/TestData.cs Outdated
@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-androidemulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@vcsjones

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@bartonjs
bartonjs merged commit d4fe4a7 into dotnet:mainJun 25, 2024
@bartonjs
bartonjs deleted the x509loader branch June 25, 2024 22:10
@pavelsavara

pavelsavara commented Jun 26, 2024

Copy link
Copy Markdown
Member

this is preventing code flow into azdo internal repo because the security scanner detects credentials.

 ! [remote rejected] main -> main (VS403654: The push was rejected because it contains one or more secrets.
Resolve the following secrets before pushing again. For help, see https://aka.ms/1ESSecretScanning.
Secrets:
commit: d4fe4a7e987584bfa4904dd1027a873029b2005d
paths:
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2710,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2723,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2745,1-29) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2752,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2802,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2881,1-30) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(2964,1-26) : SEC101/013 : PemPrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(57,149-13) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(1476,41-55) : SEC101/055 : Pkcs12PrivateKey
/src/libraries/Common/tests/System/Security/Cryptography/X509Certificates/TestData.cs(3443,13-26) : SEC101/055 : Pkcs12PrivateKey)

See also #104021

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 27, 2024
@bartonjsbartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Aug 15, 2024
@bartonjsbartonjs added the breaking-change Issue or PR that represents a breaking API or functional change over a previous release. label Sep 12, 2024
@dotnet-policy-servicedotnet-policy-serviceBot added the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjs

Copy link
Copy Markdown
MemberAuthor

Breaking change docs written. dotnet/docs#42613

@bartonjsbartonjs removed the needs-breaking-change-doc-created Breaking changes need an issue opened with https://github.com/dotnet/docs/issues/new?template=dotnet label Sep 12, 2024
@bartonjsbartonjs added the tracking This issue is tracking the completion of other related issues. label Oct 22, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Securitybreaking-changeIssue or PR that represents a breaking API or functional change over a previous release.cryptographic-docs-impactIssues impacting cryptographic docs. Cleared and reused after documentation is updated each release.new-api-needs-documentationtrackingThis issue is tracking the completion of other related issues.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@bartonjs@vcsjones@pavelsavara@stephentoub