From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mga07.intel.com (mga07.intel.com [134.134.136.100]) by mx.groups.io with SMTP id smtpd.web11.1592.1570675624387622253 for ; Wed, 09 Oct 2019 19:47:04 -0700 Authentication-Results: mx.groups.io; dkim=missing; spf=pass (domain: intel.com, ip: 134.134.136.100, mailfrom: jiaxin.wu@intel.com) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga002.jf.intel.com ([10.7.209.21]) by orsmga105.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Oct 2019 19:47:03 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.67,278,1566889200"; d="scan'208";a="205948053" Received: from fmsmsx105.amr.corp.intel.com ([10.18.124.203]) by orsmga002.jf.intel.com with ESMTP; 09 Oct 2019 19:47:03 -0700 Received: from fmsmsx153.amr.corp.intel.com (10.18.125.6) by FMSMSX105.amr.corp.intel.com (10.18.124.203) with Microsoft SMTP Server (TLS) id 14.3.439.0; Wed, 9 Oct 2019 19:47:03 -0700 Received: from shsmsx152.ccr.corp.intel.com (10.239.6.52) by FMSMSX153.amr.corp.intel.com (10.18.125.6) with Microsoft SMTP Server (TLS) id 14.3.439.0; Wed, 9 Oct 2019 19:47:02 -0700 Received: from shsmsx107.ccr.corp.intel.com ([169.254.9.33]) by SHSMSX152.ccr.corp.intel.com ([10.239.6.52]) with mapi id 14.03.0439.000; Thu, 10 Oct 2019 10:47:00 +0800 From: "Wu, Jiaxin" To: "devel@edk2.groups.io" , "lersek@redhat.com" , "Wang, Jian J" , David Woodhouse , Bret Barkelew Subject: Re: [edk2-devel] [PATCH v1 0/4] Support HTTPS HostName validation feature(CVE-2019-14553) Thread-Topic: [edk2-devel] [PATCH v1 0/4] Support HTTPS HostName validation feature(CVE-2019-14553) Thread-Index: AQHVdOXpLhbnPHTEFEiizfw0v9ZmjadBqO+AgAKyoACADahKAIABPCAQ Date: Thu, 10 Oct 2019 02:46:59 +0000 Message-ID: <895558F6EA4E3B41AC93A00D163B727416F5FA09@SHSMSX107.ccr.corp.intel.com> References: <20190927034441.3096-1-Jiaxin.wu@intel.com> <69774fe6-ea00-44b9-5468-c092dea6cd36@redhat.com> In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiOGRkYTdhNDEtZWI0Zi00OGE3LWI0OWMtZjc3NTc5NzkwMmZlIiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX05UIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE3LjEwLjE4MDQuNDkiLCJUcnVzdGVkTGFiZWxIYXNoIjoiR3dJZVdtMW1uTmwzUjlOb3N1MHp1VjJSc3Q5RmZzTmRxcDNIRENcL3NnM3cwSTVlSzQ5VFwva0N3MUhlY2lVWFlZIn0= x-ctpclassification: CTP_NT dlp-product: dlpe-windows dlp-version: 11.2.0.6 dlp-reaction: no-action x-originating-ip: [10.239.127.40] MIME-Version: 1.0 Return-Path: jiaxin.wu@intel.com Content-Language: en-US Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 SGkgIExhc3psbywNCg0KVGhhbmtzIHRoZSBjb21tZW50cy4NCg0KQmVzdCBSZWdhcmRzIQ0KSmlh eGluICANCg0KPiAtLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KPiBGcm9tOiBMYXN6bG8gRXJz ZWsgPGxlcnNla0ByZWRoYXQuY29tPg0KPiBTZW50OiBXZWRuZXNkYXksIE9jdG9iZXIgOSwgMjAx OSAxMTo1NSBQTQ0KPiBUbzogZGV2ZWxAZWRrMi5ncm91cHMuaW87IFdhbmcsIEppYW4gSiA8amlh bi5qLndhbmdAaW50ZWwuY29tPjsgV3UsIEppYXhpbg0KPiA8amlheGluLnd1QGludGVsLmNvbT47 IERhdmlkIFdvb2Rob3VzZSA8ZHdtdzJAaW5mcmFkZWFkLm9yZz47IEJyZXQNCj4gQmFya2VsZXcg PEJyZXQuQmFya2VsZXdAbWljcm9zb2Z0LmNvbT4NCj4gU3ViamVjdDogUmU6IFtlZGsyLWRldmVs XSBbUEFUQ0ggdjEgMC80XSBTdXBwb3J0IEhUVFBTIEhvc3ROYW1lDQo+IHZhbGlkYXRpb24gZmVh dHVyZShDVkUtMjAxOS0xNDU1MykNCj4gDQo+IE9uIDEwLzAxLzE5IDAxOjIxLCBMYXN6bG8gRXJz ZWsgd3JvdGU6DQo+ID4gT24gMDkvMjkvMTkgMDg6MDksIFdhbmcsIEppYW4gSiB3cm90ZToNCj4g Pj4gRm9yIHRoaXMgcGF0Y2ggc2VyaWVzLA0KPiA+PiAxLiAiIENvbnRyaWJ1dGVkLXVuZGVyOiBU aWFub0NvcmUgQ29udHJpYnV0aW9uIEFncmVlbWVudCAxLjEiIGlzIG5vdA0KPiBuZWVkZWQgYW55 IG1vcmUuDQo+ID4+ICAgUmVtb3ZlIGl0IGF0IHB1c2ggdGltZSBhbmQgbm8gbmVlZCB0byBzZW5k IGEgdjIuDQo+ID4+IDIuIFNpbmNlIGl0J3Mgc2VjdXJpdHkgcGF0Y2ggd2hpY2ggaGFkIGJlZW4g cmV2aWV3ZWQgc2VwYXJhdGVseSwgSSBzZWUgbm8NCj4gcmVhc29uIGZvciBuZXcgci1iDQo+ID4+ ICAgcmVxdWlyZWQuIFBsZWFzZSByYWlzZSBpdCBhc2FwIGlmIGFueSBvYmplY3Rpb25zLg0KPiA+ PiAzLiBBY2tlZC1ieTogSmlhbiBKIFdhbmcgPGppYW4uai53YW5nQGludGVsLmNvbT4NCj4gPg0K PiA+DQo+ID4gKiBDYW4geW91IHBsZWFzZSBjb25maXJtIHRoYXQgdGhlc2UgcGF0Y2hlcyBtYXRj aCB0aG9zZSB0aGF0IHdlDQo+ID4gZGlzY3Vzc2VkIGhlcmU6DQo+ID4NCj4gPiBodHRwczovL2J1 Z3ppbGxhLnRpYW5vY29yZS5vcmcvc2hvd19idWcuY2dpP2lkPTk2MCNjMTgNCj4gPiBodHRwczov L2J1Z3ppbGxhLnRpYW5vY29yZS5vcmcvc2hvd19idWcuY2dpP2lkPTk2MCNjMTkNCj4gDQo+IFRv IGFuc3dlciBteSBvd24gcXVlc3Rpb24sIEkndmUgbm93IGNvbXBhcmVkIHRoZSBwYXRjaGVzIGZy b20gdGhvc2UgQloNCj4gY29tbWVudHMgbGlua2VkIGFib3ZlLCB3aXRoIHRoZSBwcmVzZW50IHNl cmllcy4gSGVyZSdzIGEgbGlzdCBvZg0KPiBkaWZmZXJlbmNlcy4NCj4gDQo+ICgxKSBUaGUgc3Vi amVjdCBsaW5lcyBub3cgaW5jbHVkZSB0aGUgcmVmZXJlbmNlICIoQ1ZFLTIwMTktMTQ1NTMpIi4N Cj4gDQo+IFRoaXMgaXMgZ3JlYXQsICpidXQqIHBsZWFzZSBiZSBzdXJlIHRvIGluc2VydCBhIHNw YWNlIGNoYXJhY3RlciBiZWZvcmUNCj4gdGhlIG9wZW5pbmcgcGFyZW50aGVzaXMhIChJbiBldmVy eSBwYXRjaC4pDQo+IA0KPiAoMikgVGhlIGNvbW1pdCBtZXNzYWdlcyByZWZlcmVuY2UgYm90aCB0 aGUgQlogYW5kIHRoZSBDVkUgbnVtYmVyLg0KPiANCj4gR29vZC4NCj4gDQo+ICgzKSBJbiB0aGUg Y29tbWl0IG1lc3NhZ2VzLCB0aGUgbGluZQ0KPiANCj4gICBDb250cmlidXRlZC11bmRlcjogVGlh bm9Db3JlIENvbnRyaWJ1dGlvbiBBZ3JlZW1lbnQgMS4wDQo+IA0KPiBoYXMgYmVlbiB1cGdyYWRl ZCB0bw0KPiANCj4gICBDb250cmlidXRlZC11bmRlcjogVGlhbm9Db3JlIENvbnRyaWJ1dGlvbiBB Z3JlZW1lbnQgMS4xDQo+IA0KPiBJIHRoaW5rIHRoaXMgaXMgd3JvbmcuIFRoZSBsaW5lcyBzaG91 bGQgaGF2ZSBiZWVuIHJlbW92ZWQsIGR1ZSB0byB0aGUNCj4gU1BEWCBhZG9wdGlvbi4gUGxlYXNl IHVwZGF0ZSBhbGwgdGhlIGNvbW1pdCBtZXNzYWdlcy4NCj4gDQo+ICg0KSBDb3B5cmlnaHQgbm90 aWNlIHVwZGF0ZXMgYXJlIGdvbmUgZnJvbSB0aGUgcGF0Y2hlcy4NCj4gDQo+IFRoYXQncyBmaW5l OiB0aGUgcmVhc29uIGlzIHRoYXQgdGhlIHVuZGVybHlpbmcgZmlsZXMgaGF2ZSBzZWVuIHRoZWly DQo+IGNvcHlyaWdodCBub3RpY2VzIHVwZGF0ZWQsIG1lYW53aGlsZS4NCj4gDQo+IA0KPiBPdGhl cndpc2UsIHRoZSBwYXRjaGVzIChjb2RlLCBjb21taXQgbWVzc2FnZXMsIGFuZCBmZWVkYmFjayB0 YWdzKSBhcmUNCj4gaWRlbnRpY2FsLg0KPiANCj4gQmVmb3JlIHlvdSBwdXNoIHRoZSBwYXRjaGVz IChvciBwb3N0IGEgdjIpLCBwbGVhc2UgZml4IGlzc3VlcyAoMSkgYW5kICgzKS4NCj4gDQo+IE5v dywgcmVnYXJkaW5nIHRoZSBvdGhlciBzZXQgb2YgcXVlc3Rpb25zOg0KPiANCj4gPiAqIEluIHRo ZSBCWiwgRGF2aWQgYW5kIEJyZXQgcmFpc2VkIHNvbWUgcXVlc3Rpb25zOg0KPiA+DQo+ID4gaHR0 cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3dfYnVnLmNnaT9pZD05NjAjYzMxDQo+ID4g aHR0cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3dfYnVnLmNnaT9pZD05NjAjYzMyDQo+ ID4gaHR0cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3dfYnVnLmNnaT9pZD05NjAjYzM1 DQo+ID4gaHR0cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3dfYnVnLmNnaT9pZD05NjAj YzM2DQo+ID4NCj4gPiBhbmQNCj4gPg0KPiA+IGh0dHBzOi8vYnVnemlsbGEudGlhbm9jb3JlLm9y Zy9zaG93X2J1Zy5jZ2k/aWQ9OTYwI2M0MA0KPiA+DQo+ID4gVGhlIGxhdGVzdCBjb21tZW50IGlu IHRoZSBidWcgaXMgYyM0MS4gSSdtIG5vdCB1bmRlciB0aGUgaW1wcmVzc2lvbiB0aGF0DQo+ID4g YWxsIGNvbmNlcm5zIHJhaXNlZCBieSBEYXZpZCBhbmQgQnJldCBoYXZlIGJlZW4gYWRkcmVzc2Vk IChvcg0KPiA+IGFiYW5kb25lZCkuIEknZCBsaWtlIERhdmlkIGFuZCBCcmV0IHRvIEFDSyB0aGUg cGF0Y2hlcy4NCj4gDQo+IEknbGwgZmlyc3QgaGF2ZSB0byBwcm9jZXNzIHRoZSBuZXcgY29tbWVu dHMgZG93bi10aHJlYWQuDQo+IA0KPiBUaGFua3MNCj4gTGFzemxvDQo=