)]}'
{
  "commit": "64393b57e8734b92a6ba784bcfc02b1aa01e5ff2",
  "tree": "b40e43f2afac858f26ad8a629060d5a928ddb0fc",
  "parents": [
    "d8090a173b7e2050a75a0c1a6fcd32b4198069e7"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Mon Oct 03 11:26:39 2022 -0400"
  },
  "committer": {
    "name": "Boringssl LUCI CQ",
    "email": "boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com",
    "time": "Mon Oct 03 20:42:56 2022 +0000"
  },
  "message": "Default SSL_set_enforce_rsa_key_usage to enabled.\n\nUpdate-Note: Clients will now require RSA server certificates used in\nTLS 1.2 and earlier to include the keyEncipherment or digitalSignature\nbit. keyEncipherment is required if using RSA key exchange.\ndigitalSignature is required if using ECDHE_RSA key exchange.\n\nWe already required this for each of ECDSA, TLS 1.3, and servers\nverifying client certificates, so this just fills in the remaining hole.\nChrome has also enforced this for some time with publicly-trusted\ncertificates. For now, the SSL_set_enforce_rsa_key_usage API still\nexists where we need to turn this off.\n\nFixed: 519\nChange-Id: Ia440b00b60a224fa608702439aa120d633d81ddc\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/54606\nAuto-Submit: David Benjamin \u003cdavidben@google.com\u003e\nCommit-Queue: Adam Langley \u003cagl@google.com\u003e\nReviewed-by: Adam Langley \u003cagl@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "4d56d37283430f9b7ac971c4ecd8a852feeba4f3",
      "old_mode": 33188,
      "old_path": "ssl/ssl_lib.cc",
      "new_id": "a6ca0ab96266475384429e73970de18d4ba09912",
      "new_mode": 33188,
      "new_path": "ssl/ssl_lib.cc"
    },
    {
      "type": "modify",
      "old_id": "5c6ef4f1d644d25aab3fb11cef2d1d0f52de4508",
      "old_mode": 33188,
      "old_path": "ssl/test/runner/runner.go",
      "new_id": "655226ca7a393f387b1bc2874ba95a6dfe6d4c2f",
      "new_mode": 33188,
      "new_path": "ssl/test/runner/runner.go"
    },
    {
      "type": "modify",
      "old_id": "2c7fa08ac0fb2530437f9995745c0eb766616765",
      "old_mode": 33188,
      "old_path": "ssl/test/test_config.cc",
      "new_id": "0230bdb95837707cca3a56244d4630a194d30423",
      "new_mode": 33188,
      "new_path": "ssl/test/test_config.cc"
    },
    {
      "type": "modify",
      "old_id": "1a21ac147a8d556cc8ae930c90b1196068e7dc93",
      "old_mode": 33188,
      "old_path": "ssl/test/test_config.h",
      "new_id": "6b158911cfdc04811643dfb897e9a185a3f4da7e",
      "new_mode": 33188,
      "new_path": "ssl/test/test_config.h"
    }
  ]
}
