From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mga05.intel.com (mga05.intel.com [192.55.52.43]) by mx.groups.io with SMTP id smtpd.web11.1787.1571969916292076252 for ; Thu, 24 Oct 2019 19:18:36 -0700 Authentication-Results: mx.groups.io; dkim=missing; spf=pass (domain: intel.com, ip: 192.55.52.43, mailfrom: jiaxin.wu@intel.com) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from fmsmga006.fm.intel.com ([10.253.24.20]) by fmsmga105.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 24 Oct 2019 19:18:35 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.68,226,1569308400"; d="scan'208,217";a="399966584" Received: from fmsmsx108.amr.corp.intel.com ([10.18.124.206]) by fmsmga006.fm.intel.com with ESMTP; 24 Oct 2019 19:18:35 -0700 Received: from fmsmsx609.amr.corp.intel.com (10.18.126.89) by FMSMSX108.amr.corp.intel.com (10.18.124.206) with Microsoft SMTP Server (TLS) id 14.3.439.0; Thu, 24 Oct 2019 19:18:35 -0700 Received: from fmsmsx609.amr.corp.intel.com (10.18.126.89) by fmsmsx609.amr.corp.intel.com (10.18.126.89) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1713.5; Thu, 24 Oct 2019 19:18:35 -0700 Received: from shsmsx153.ccr.corp.intel.com (10.239.6.53) by fmsmsx609.amr.corp.intel.com (10.18.126.89) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256) id 15.1.1713.5 via Frontend Transport; Thu, 24 Oct 2019 19:18:34 -0700 Received: from shsmsx107.ccr.corp.intel.com ([169.254.9.33]) by SHSMSX153.ccr.corp.intel.com ([10.239.6.53]) with mapi id 14.03.0439.000; Fri, 25 Oct 2019 10:18:33 +0800 From: "Wu, Jiaxin" To: Sivaraman Nainar , "devel@edk2.groups.io" , "Fu, Siyuan" , Laszlo Ersek CC: Ramesh R. , "Madhan B. Santharam" , "Arun Subramanian B" , Arun Sura Soundara Pandian , Bhuvaneshwari M R Subject: Re: TianoCore Bug 960 (HTTPS_HostName_Validation) Security Fix Thread-Topic: TianoCore Bug 960 (HTTPS_HostName_Validation) Security Fix Thread-Index: AdWKShrVA+mwHAi9Qua/V/OHLgpEYwAj7gyw Date: Fri, 25 Oct 2019 02:18:33 +0000 Message-ID: <895558F6EA4E3B41AC93A00D163B727416F84759@SHSMSX107.ccr.corp.intel.com> References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiYWRiZWJmMjMtOWQ5ZS00OWY3LWJlZWQtZTJjZTgzNzM2MmZiIiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX05UIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE3LjEwLjE4MDQuNDkiLCJUcnVzdGVkTGFiZWxIYXNoIjoiQmpwOWYrS3hlYW51ZHJvbXF1Q2ZMSlMwSmZFK2p1TjZtb1VTY0p0VU1Ea2VGSWtGeW54OTc0RWNreGhhYUVJaiJ9 x-ctpclassification: CTP_NT dlp-product: dlpe-windows dlp-version: 11.2.0.6 dlp-reaction: no-action x-originating-ip: [10.239.127.40] MIME-Version: 1.0 Return-Path: jiaxin.wu@intel.com Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_895558F6EA4E3B41AC93A00D163B727416F84759SHSMSX107ccrcor_" --_000_895558F6EA4E3B41AC93A00D163B727416F84759SHSMSX107ccrcor_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi Siva, Let's wait the new series patches from Laszlo. Please also help to verify t= he new coming patches if possible. Laszlo, Can you also CC the new patches to Siva for the more verification? Thanks, Jiaxin From: Sivaraman Nainar Sent: Thursday, October 24, 2019 5:06 PM To: devel@edk2.groups.io; Wu, Jiaxin ; Fu, Siyuan Cc: Ramesh R. ; Madhan B. Santharam ; Aru= n Subramanian B ; Arun Sura Soundara Pandian ; Bhuvaneshwari M R Subject: reg: TianoCore Bug 960 (HTTPS_HostName_Validation) Security Fix Hello Jiaxin: Could you please update when the security fixes for Host Name Validation wi= ll be submitted in the Main tree? UEFI 2.8 specification updated with the Host Name validation support alread= y. -Siva --_000_895558F6EA4E3B41AC93A00D163B727416F84759SHSMSX107ccrcor_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Hi Siva,

 

Let’s wait the new series patches from Laszlo.= Please also help to verify the new coming patches if possible.

 

Laszlo,

 

Can you also CC the new patches to Siva for the more= verification?

 

Thanks,

Jiaxin

 

 

From: Siv= araman Nainar <sivaramann@amiindia.co.in>
Sent: Thursday, October 24, 2019 5:06 PM
To: devel@edk2.groups.io; Wu, Jiaxin <jiaxin.wu@intel.com>; Fu= , Siyuan <siyuan.fu@intel.com>
Cc: Ramesh R. <rameshr@ami.com>; Madhan B. Santharam <madha= ns@ami.com>; Arun Subramanian B <arunsubramanianb@ami.com>; Arun S= ura Soundara Pandian <arunsuras@amiindia.co.in>; Bhuvaneshwari M R &l= t;bhuvaneshwarimr@amiindia.co.in>
Subject: reg: TianoCore Bug 960 (HTTPS_HostName_Validation) Security= Fix

 

Hello Jiaxin:

 

Could you please update when the security fixes for = Host Name Validation will be submitted in the Main tree?

 

UEFI 2.8 specification updated with the Host Name va= lidation support already.

 

-Siva

--_000_895558F6EA4E3B41AC93A00D163B727416F84759SHSMSX107ccrcor_--