Account Options

  1. Sign in
The old Google Groups will be going away soon.
Switch to the new Google Groups.
Google Groups Home
« Groups Home
CNNIC Root Inclusion Request
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Kathleen Wilson  
View profile  
 More options Oct 13 2009, 1:59 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kathleen95...@yahoo.com>
Date: Tue, 13 Oct 2009 10:59:27 -0700 (PDT)
Local: Tues, Oct 13 2009 1:59 pm
Subject: CNNIC Root Inclusion Request
As per the CA Schedule at https://wiki.mozilla.org/CA:Schedule the
China Internet Network Information Center (CNNIC) is the next request
in the queue for public discussion.

CNNIC, a non-profit organization, is the state network information
center of China. CNNIC takes orders from the Ministry of Information
Industry (MII) to conduct daily business, while it is administratively
operated by the Chinese Academy of Sciences (CAS). The CNNIC Steering
Committee, a working group composed of well-known experts and
commercial representatives in domestic Internet community, supervises
and evaluates the structure, operation and administration of CNNIC.

CNNIC has applied to add the “CNNIC ROOT” root certificate and enable
the Websites trust bit.

The request is documented in the following bug:

https://bugzilla.mozilla.org/show_bug.cgi?id=476766

And in the pending certificates list here:

http://www.mozilla.org/projects/security/certs/pending/#CNNIC

Summary of Information Gathered and Verified:

https://bugzilla.mozilla.org/attachment.cgi?id=405902

Noteworthy points:

* The CPS has been translated into English:
http://www.cnnic.cn/uploadfiles/pdf/2009/7/3/163452.pdf

* There is currently one internally-operated subordinate CA named
CNNIC SSL, which offers only SSL certificates. SSL certificates may be
issued to general public, including enterprise, government,
organization, league, individual, etc.

* The request is to enable the Websites trust bit.

** CPS Section 3.2 Requires proof of identification of the certificate
applicant or organization representative. Enterprises, government
organizations, institutions, etc. must provide the organization code
certificate or legal person business license (each page affixed with
an official seal).
** CPS Section 3.2: The inputer at the Local Registration Authority
carries out preliminary examination. Through the domain name
registration information inquiry (whois), the inputer gets the
information of the domain name registrar of the domain name
certificate application, checks whether the domain name registrar is
consistent with the domain name certificate applicant, and determines
whether the domain name certificate applicant indeed has this domain
name through preliminary examination.
** CPS Section 3.2: The RA auditor checks whether the legal domain
name subscriber is consistent with the certificate applicant (also
using the whois function), and whether the information is true, and
compares it with the application information in the RA system. The RA
auditor confirms the information with the director and the handler
respectively through telephone.
** CPS Section 4.1.1.1: “The handlers for applying for domain name
certificates must go to a Local Registration Authority of CNNIC
Trusted Network Service Center designated by the CNNIC to submit
applications.”
** CPS Section 4.1.1.2: “Documents used to prove the certificate
subscriber organizations, handlers (subscribers) and identity of
handlers are explained in Section 3.2 of this CPS, and applicants
shall carry out application operations according to Section 3.2 of
this CPS. After the Registration Authority of CNNIC Trusted Network
Service Center completed the procedure of verifying identity, it
emails the first thirteen numbers of the reference number and
authorization code to handler and sends the last three number of these
two code through cellphone. And make a paper ‘certificate on approval
for CNNIC SSL Certificates’ via a safe mailing method to the
certificate application handler.”
** CPS Section 4.1.2.1: “The steps for issuing and accepting single
domain and wildcard domain certificates are as follows: The
certificate application handler generates a certificate request CSR in
the Web server. The certificate application handler accesses the CNNIC
certificate download page, submits the CSR and puts in the reference
number and the authorization code. CNNIC Trusted Network Service
Center system automatically checks the completeness of the CSR. CNNIC
Trusted Network Service Center issues a certificate and the
certificate application handler downloads it and then installs it.”

* Test website: https://www.enum.cn/

* CNNIC provides CRL, NextUpdate is 12 hours
* CNNIC does not currently provide OCSP

* Audit: CNNIC is audited every 12 months, according to their CPS.
CNNIC was recently audited by Ernst & Young. https://cert.webtrust.org/ViewSeal?id=935

* Other
** Wildcard SSL certs are provided, but they are always OV.

This begins the one-week discussion period. After that week, I will
provide a summary of issues noted and action items. If there are no
outstanding issues, then this request can be approved. If there are
outstanding issues or action items, then an additional discussion may
be needed as follow-up.

Kathleen


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Oct 14 2009, 9:04 pm
Newsgroups: mozilla.dev.security.policy
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Thu, 15 Oct 2009 03:04:10 +0200
Local: Wed, Oct 14 2009 9:04 pm
Subject: Re: CNNIC Root Inclusion Request
On 10/13/2009 07:59 PM, Kathleen Wilson:

> As per the CA Schedule at https://wiki.mozilla.org/CA:Schedule the
> China Internet Network Information Center (CNNIC) is the next request
> in the queue for public discussion.

No particular immediate issues seen, fine CA. Note to the representative
of CNNIC that the cross signing of other CA certificates has not been
disclosed properly in the CA policy. This should be corrected, a mere
disclaimer is not sufficient.

--
Regards

Signer:  Eddy Nigg, StartCom Ltd.
XMPP:    start...@startcom.org
Blog:    http://blog.startcom.org/
Twitter: http://twitter.com/eddy_nigg


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kathleen Wilson  
View profile  
 More options Oct 19 2009, 2:28 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kathleen95...@yahoo.com>
Date: Mon, 19 Oct 2009 11:28:11 -0700 (PDT)
Local: Mon, Oct 19 2009 2:28 pm
Subject: Re: CNNIC Root Inclusion Request
Thanks Eddy!

Does anyone else have an opinion about this request?
Shall I proceed with making the recommendation for approval?

Kathleen


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ian G  
View profile  
 More options Oct 19 2009, 4:33 pm
Newsgroups: mozilla.dev.security.policy
From: Ian G <i...@iang.org>
Date: Mon, 19 Oct 2009 22:33:19 +0200
Local: Mon, Oct 19 2009 4:33 pm
Subject: Re: CNNIC Root Inclusion Request
On 19/10/2009 20:28, Kathleen Wilson wrote:

> Thanks Eddy!

> Does anyone else have an opinion about this request?
> Shall I proceed with making the recommendation for approval?

I read the audit report briefly, nothing spotted.  On the whole I could
not see anything there that I would complain about.

iang


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kathleen Wilson  
View profile  
 More options Oct 21 2009, 4:37 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kathleen95...@yahoo.com>
Date: Wed, 21 Oct 2009 13:37:13 -0700 (PDT)
Local: Wed, Oct 21 2009 4:37 pm
Subject: Re: CNNIC Root Inclusion Request

>  Note to the representative
> of CNNIC that the cross signing of other CA certificates has not been
> disclosed properly in the CA policy. This should be corrected, a mere
> disclaimer is not sufficient.

Eddy, CNNIC is happy to update their CPS as per your suggestion.
However, it is unclear as to what would be considered sufficient
disclosure. Do you happen to have an example that you could point them
to?  Or perhaps a suggestion about what they could include in their
CPS to satisfy this request?

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Oct 22 2009, 6:08 am
Newsgroups: mozilla.dev.security.policy
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Thu, 22 Oct 2009 12:08:23 +0200
Local: Thurs, Oct 22 2009 6:08 am
Subject: Re: CNNIC Root Inclusion Request
On 10/21/2009 10:37 PM, Kathleen Wilson:

>>   Note to the representative
>> of CNNIC that the cross signing of other CA certificates has not been
>> disclosed properly in the CA policy. This should be corrected, a mere
>> disclaimer is not sufficient.

> Eddy, CNNIC is happy to update their CPS as per your suggestion.
> However, it is unclear as to what would be considered sufficient
> disclosure. Do you happen to have an example that you could point them
> to?  Or perhaps a suggestion about what they could include in their
> CPS to satisfy this request?

Basically it should include the circumstance for issuing (cross-signing)
and its relevant requirements, suspension,and revocation of the
cross-signed certificate. For example if the cross-signed root is
handled by the CA or if a WebTrust audit must be completed for the
cross-signed roots. I think the WebTrust audit has relevant criteria for
sub and cross signing as part of the CAs disclosure if its key and
certificate life cycle.

--
Regards

Signer:  Eddy Nigg, StartCom Ltd.
XMPP:    start...@startcom.org
Blog:    http://blog.startcom.org/
Twitter: http://twitter.com/eddy_nigg


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kathleen Wilson  
View profile  
 More options Oct 22 2009, 1:47 pm
Newsgroups: mozilla.dev.security.policy
From: Kathleen Wilson <kathleen95...@yahoo.com>
Date: Thu, 22 Oct 2009 10:47:24 -0700 (PDT)
Local: Thurs, Oct 22 2009 1:47 pm
Subject: Re: CNNIC Root Inclusion Request
Thank you, Eddy and Iang, for reviewing this request and providing
your comments and feedback.  Your contributions are greatly
appreciated.

This discussion was in regards to the request from the China Internet
Network Information Center (CNNIC) to add the “CNNIC ROOT” root
certificate and enable the Websites trust bit.

CNNIC intends to update their CPS in regards to Eddy’s suggestion
about further disclosing their policies about cross-signing. I do not
plan to track this action item.

I will post a summary of the request and my recommendation for
approval in the bug:

https://bugzilla.mozilla.org/show_bug.cgi?id=476766

I am now closing this discussion. Any further follow-up on this
request should be added directly to the bug.

Thanks,
Kathleen


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cghadsdsd  
View profile  
 More options Nov 9 2009, 12:02 am
Newsgroups: mozilla.dev.security.policy
From: cghadsdsd <chris.ca...@hotmail.com>
Date: Sun, 8 Nov 2009 21:02:32 -0800 (PST)
Local: Mon, Nov 9 2009 12:02 am
Subject: Re: CNNIC Root Inclusion Request
On 10月14日, 上午1时59分, Kathleen Wilson <kathleen95...@yahoo.com> wrote:

http://www.x021.com.cn
http://www.chinaxbj.org.cn

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
cghadsdsd  
View profile  
 More options Nov 9 2009, 12:02 am
Newsgroups: mozilla.dev.security.policy
From: cghadsdsd <chris.ca...@hotmail.com>
Date: Sun, 8 Nov 2009 21:02:53 -0800 (PST)
Local: Mon, Nov 9 2009 12:02 am
Subject: Re: CNNIC Root Inclusion Request
 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »