Hi Daniel,
I assume that “inactive” in this case means that all certificates issued to that CA (name, key tuple) and chain to an Apple- or Mozilla-trusted root are expired or revoked. Even if there were an expectation that such CAs continue to provide revocation information, I struggle to see how maintaining access to that CA’s published revocation information would be valuable to a Relying Party. Relying parties will perform certification path validation on presented certificate chains, and this will fail upon encountering no valid paths from that CA (name, key tuple) back to a trust anchor. Any revocation artifacts issued by the CA in question have no value to the RP, as the CA itself is not trusted.
Thanks,
Corey
--
You received this message because you are subscribed to the Google Groups "CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public+un...@ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/44078b55-141b-4dc5-a7f9-c3e6a7bbaa90n%40ccadb.org.
Hi Daniel,
As far as I’m aware, CCADB entries are not removed after the corresponding certificate expires/is revoked, so there’s a lot of old data present. In addition to CRL URIs, you’ll also find links to audit documents from 2017, etc. Definitely not useful for an RP making trust decisions today based on the data but may be useful when doing a historical analysis.
For those who care only about the set of unexpired/not revoked CA certificates (such as for your analysis), including the PEM text of the corresponding certificate, or at the very least the notBefore/notAfter values in the “AllCertificateRecordsCSVFormat” report would be useful. I know that I’ve had to write logic that correlates the information in the “AllCertificateRecordsCSVFormat” report with another data source to get the full picture at least a few times, and I imagine others have had to do the same thing as well.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/CAPSmj0R7qWBX7GEko7L5c3D0mhvRox%3DF6ydAJHgb2%3DU0JxbGmg%40mail.gmail.com.
Thanks, Kathleen. I think these are very useful improvements to CCADB reporting.
Thanks,
Corey
From: Kathleen Wilson <kwi...@mozilla.com>
Sent: Monday, May 8, 2023 6:15 PM
To: CCADB Public <pub...@ccadb.org>
Cc: Corey Bonnell <Corey....@digicert.com>
Subject: Re: Broken CRL URLs in CCADB
We've updated the report
--
You received this message because you are subscribed to a topic in the Google Groups "CCADB Public" group.
To unsubscribe from this topic, visit https://groups.google.com/a/ccadb.org/d/topic/public/CKoJEAO6Qho/unsubscribe.
To unsubscribe from this group and all its topics, send an email to public+un...@ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/bfbf99ca-c9c9-462d-91d3-39335c8d2fb8n%40ccadb.org.
>> We've updated the report>> to add two more columns (Valid From, Valid To).
>> We've also created another report:>> It has two columns: SHA-256 Fingerprint, X.509 Certificate (PEM)
> I can download this new CSV report if I access this URL in a browser, but with wget I'm getting an HTML page instead.
>> We've also created another report:
>> It has two columns: SHA-256 Fingerprint, X.509 Certificate (PEM)
> I can download this new CSV report if I access this URL in a browser, but with wget I'm getting an HTML page instead.
Hi Kathleen,
The new reports contain very useful information that was not easily available previously. However, it appears that the method in which the report information is downloaded is different from the other reports. For example, the report containing the PEM text of all Mozilla-trust serverAuth roots [1] is directly available as a CSV. However, one of the new reports, such as the PEM texts of all certificates in CCADB, must first be accessed via a browser and JavaScript be executed to download the report. This download process hinders automation for tooling that consume these reports, as now the report must periodically be downloaded by someone manually or the tooling must execute the JavaScript to download the actual report CSV. Would it be possible to modify the new reports so that they are readily available as CSV files?
Thanks,
Corey
From: pub...@ccadb.org <pub...@ccadb.org> On Behalf Of Kathleen Wilson
Sent: Monday, May 15, 2023 6:13 PM
To: CCADB Public <pub...@ccadb.org>
Subject: Re: Broken CRL URLs in CCADB
--
You received this message because you are subscribed to the Google Groups "CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public+un...@ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/97347114-1da1-47f6-9966-036faf352b8an%40ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/DM6PR14MB2186188F73E34F52EE12E88692799%40DM6PR14MB2186.namprd14.prod.outlook.com.
However, one of the new reports, such as the PEM texts of all certificates in CCADB, must first be accessed via a browser and JavaScript be executed to download the report. This download process hinders automation for tooling that consume these reports, as now the report must periodically be downloaded by someone manually or the tooling must execute the JavaScript to download the actual report CSV. Would it be possible to modify the new reports so that they are readily available as CSV files?
Would it be possible to split it into multiple reports (e.g. 16
different reports based on the first hex digit of the fingerprint)?
For example:
https://ccadb.my.salesforce-sites.com/ccadb/AllCertificatePEMsCSVFormat?NotBeforeYear=1999
Would provide the certificate PEMs for which the CCADB record has a ‘Valid From (GMT)’ field that contains 1999.
It looks like the first year for which there is data is 1994.
It is a good idea but it results too many separate reports.
What about grouping the certificates only by decades, which would result only for reports:
199x
200x
201x
202x
Sándor
From: pub...@ccadb.org <pub...@ccadb.org> On Behalf Of Kathleen Wilson
Sent: Thursday, May 18, 2023 11:06 PM
To: CCADB Public <pub...@ccadb.org>
Cc: Andrew Ayer <ag...@andrewayer.name>; CCADB Public <pub...@ccadb.org>; Kathleen Wilson <kwi...@mozilla.com>
Subject: Re: Broken CRL URLs in CCADB
Would it be possible to split it into multiple reports (e.g. 16
--
You received this message because you are subscribed to the Google Groups "CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public+un...@ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/e4ca526b-d690-485d-83f9-b4f92c00bb45n%40ccadb.org.
Hi Kathleen,
I tested the decade version for each decades and it was working fine.
Thanks for it,
Sándor
From: pub...@ccadb.org <pub...@ccadb.org> On Behalf Of Kathleen Wilson
Sent: Tuesday, May 23, 2023 12:03 AM
To: CCADB Public <pub...@ccadb.org>
Subject: Re: Broken CRL URLs in CCADB
The AllCertificatePEMsCSVFormat report has been update to accept one parameter: either NotBeforeYear or NotBeforeDecade
--
You received this message because you are subscribed to the Google Groups "CCADB Public" group.
To unsubscribe from this group and stop receiving emails from it, send an email to public+un...@ccadb.org.
To view this discussion on the web visit https://groups.google.com/a/ccadb.org/d/msgid/public/54d8228b-d9fa-4e4e-a5eb-4898bdd89156n%40ccadb.org.