• Quentin Smith's avatar
    [release-branch.go1.7] crypto/x509: read Darwin trust settings for root CAs · 26741a15
    Quentin Smith authored
    Darwin separately stores bits indicating whether a root certificate
    should be trusted; this changes Go to read and use those when
    initializing SystemCertPool.
    
    Unfortunately, the trust API is very slow. To avoid a delay of up to
    0.5s in initializing the system cert pool, we assume that
    the trust settings found in kSecTrustSettingsDomainSystem will always
    indicate trust. (That is, all root certs Apple distributes are trusted.)
    This is not guaranteed by the API but is true in practice.
    
    In the non-cgo codepath, we do not have that benefit, so we must check
    the trust status of every certificate. This causes about 0.5s of delay
    in initializing the SystemCertPool.
    
    On OS X 10.11 and older, the "security" command requires a certificate
    to be provided in a file and not on stdin, so the non-cgo codepath
    creates temporary files for each certificate, further slowing initialization.
    
    Updates #18141.
    
    Change-Id: If681c514047afe5e1a68de6c9d40ceabbce54755
    Reviewed-on: https://go-review.googlesource.com/33721
    Run-TryBot: Quentin Smith <quentin@golang.org>
    TryBot-Result: Gobot Gobot <gobot@golang.org>
    Reviewed-by: 's avatarRuss Cox <rsc@golang.org>
    Reviewed-on: https://go-review.googlesource.com/33727
    26741a15
Name
Last commit
Last update
..
archive Loading commit data...
bufio Loading commit data...
builtin Loading commit data...
bytes Loading commit data...
cmd Loading commit data...
compress Loading commit data...
container Loading commit data...
context Loading commit data...
crypto Loading commit data...
database/sql Loading commit data...
debug Loading commit data...
encoding Loading commit data...
errors Loading commit data...
expvar Loading commit data...
flag Loading commit data...
fmt Loading commit data...
go Loading commit data...
hash Loading commit data...
html Loading commit data...
image Loading commit data...
index/suffixarray Loading commit data...
internal Loading commit data...
io Loading commit data...
log Loading commit data...
math Loading commit data...
mime Loading commit data...
net Loading commit data...
os Loading commit data...
path Loading commit data...
reflect Loading commit data...
regexp Loading commit data...
runtime Loading commit data...
sort Loading commit data...
strconv Loading commit data...
strings Loading commit data...
sync Loading commit data...
syscall Loading commit data...
testing Loading commit data...
text Loading commit data...
time Loading commit data...
unicode Loading commit data...
unsafe Loading commit data...
vendor/golang_org/x/net Loading commit data...
Make.dist Loading commit data...
all.bash Loading commit data...
all.bat Loading commit data...
all.rc Loading commit data...
androidtest.bash Loading commit data...
bootstrap.bash Loading commit data...
buildall.bash Loading commit data...
clean.bash Loading commit data...
clean.bat Loading commit data...
clean.rc Loading commit data...
cmp.bash Loading commit data...
iostest.bash Loading commit data...
make.bash Loading commit data...
make.bat Loading commit data...
make.rc Loading commit data...
naclmake.bash Loading commit data...
nacltest.bash Loading commit data...
race.bash Loading commit data...
race.bat Loading commit data...
run.bash Loading commit data...
run.bat Loading commit data...
run.rc Loading commit data...