New issue
Advanced search Search tips

Issue 594441 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 598526
Owner: ----
Closed: Jul 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Certificate Transparency - GDCA CT Log Server Inclusion

Reported by hanjie77...@gmail.com, Mar 14 2016

Issue description

What steps will reproduce the problem?
Certificate Transparency - GDCA CT Log Server Inclusion

Log Server URL: https://ct.gdca.com.cn
HTTPS supported: yes
MMD: 24 hours

Contact Information:
- email: capoc@gdca.com.cn;
- phone number:  +86(20)83487228-805
- Log Operator: Wang Shengnan

Server public key: Attached file: gdca-ct-key-public.pem
Accepted Roots: Attached file: gdca-trusted-roots.pem

the "Merge Delay Monitor Root" already add in the trusted roots file.

Log Description and Policy: Currently, the only policy in place is that the certificate chain to a publicly trusted root certificate.  However, during the testing and log inclusion process, we are only including the GDCA trusted roots as authorized. Additional root entries will be evaluated after receiving an inclusion request. We will likely develop our policies further based on the results from the discussions in the Trans working group and our own internal policies.  Such policies may include an enforcement of BR and EV standards, a requirement for at least organizational vetting on the certificate, minimum key sizes and hash algorithms, and similar checks.

Chrome Version       : 48.0.2564.116

 
gdca-ct-key-public.pem
178 bytes Download
gdca-trusted-roots.pem
3.0 KB Download
Labels: Te-NeedsFurtherTriage

Comment 2 Deleted

Can you tell me if there is any other steps need to be taken. Thank you!

Comment 4 by eranm@chromium.org, Jul 8 2016

Mergedinto: 598526
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment