New issue
Advanced search Search tips

Issue 768309 link

Starred by 5 users

Issue metadata

Status: WontFix
Owner:
Closed: Nov 29
Cc:
Components:
EstimatedDays: ----
NextAction: 2018-04-20
OS: ----
Pri: 3
Type: Bug


Show other hotlists

Hotlists containing this issue:
Hotlist-1


Sign in to add a comment

Inclusion of GDCA CT Log 2

Reported by wangsn1...@gmail.com, Sep 25 2017

Issue description

Contact Information:
  - Log Operator: GDCA
  - Email: wangsn1206@gmail.com
  - Telephone: +86(20)83487228-805
  - Authorized Personnel: Wang Shengnan, Zheng Huitao

HTTPS Endpoint: https://log2.gdca.com.cn/

Maximum Merge Delay: 24 hours

Public Key: see attached (gdca-log2-pubkey.der)

Accepted Roots: see attached (gdca-trusted-roots.pem)

the "Merge Delay Monitor Root" already add in the trusted roots file.

Description:
  - Open acceptance policy: This log is hosted on the Google Cloud in the U.S, and accepts all roots that are enabled for the server authentication trust purpose in one or more of the Microsoft, Mozilla, Apple and Google root programs.  We will update this log's list of accepted roots from time to time in accordance with this policy.
  - Free: There is no cost to CAs for having a root accepted by this log.  There is also no cost for submitting certificates/precertificates to this log.  There are no contracts to sign at present, but we reserve the right to require contracts in the future.
  - Rate limits: Submissions are rate-limited by IP address.  Upon request, GDCA will consider raising a submitter's rate limit, but GDCA reserves the right to decline such requests (if GDCA does not believe there is sufficient spare capacity) or to charge for this service in the future.
  - Reasonable Commercial Efforts: GDCA expects to be able to accept submissions for newly issued certificates, but GDCA asks that submitters refrain from submitting (to this log) large numbers of certificates that were not recently issued.  GDCA reserves the right to remove (temporarily or permanently) any root from this log's list of accepted roots, without prior notice, if GDCA is unable to cope with the rate of submissions associated with that root.
  - Disclaimer: GDCA's CT Log is provided "AS-IS".  The log is an aggregate of information from GDCA and third parties not under GDCA's control and, therefore, GDCA does not guarantee accuracy of information from third party sources or contributors.  Further, GDCA does not guarantee the performance or availability to any end users of the log, whether to certification authorities or other submitters or to any parties or individuals desiring to read the status or the content of the log.  We reserve the right to update this log policy from time to time.
 
gdca-log2-pubkey.der
91 bytes Download
gdca-trusted-roots.pem
4.0 KB Download

Comment 1 by eranm@chromium.org, Sep 25 2017

Cc: rsleevi@chromium.org
Labels: TE-NeedsTriageHelp
Adding the label 'TE-NeedsTriageHelp' as the issue is out of TE's scope.
Components: Internals>Network>CertTrans
Is there a planned timescale in which GDCA plans to operate this log, at this IP? For example, is this something GDCA has made plans for only one year of operation, or multiple years?

I ask in light of the discussion surrounding the temporal sharding at https://groups.google.com/a/chromium.org/d/msg/ct-policy/_eXIfMf7LQQ/rt9GG3orAwAJ , which provides for clear timelines for how long a log will operate until it's rotated or gracefully shut down.

Regarding monitoring, I believe this meets sufficient criteria to begin monitoring, although we should wait for further details on policy.
Labels: -TE-NeedsTriageHelp Needs-Feedback
Hi Ryan,

Thanks for your comment.

We read the discussion you referred, and we came up with the following planned timescale after discussion within our team:
Certificate Expiry Range: [2018-01-01 00:00:00 UTC, 2023-01-01 00:00:00 UTC)

Let me know if you have any further questions.

Thanks.
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 16 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "rsleevi@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Owner: asymmetric@chromium.org
Status: Assigned (was: Unconfirmed)
NextAction: 2018-04-20
The NextAction date has arrived: 2018-04-20
Owner: katjoyce@google.com
Hi there, I'm just setting up the monitoring for these Logs, and I notice that the email address provided is what looks to be a personal gmail address.  I also notice that the previously submitted GDCA Logs used a gdca business email address - capoc@gdca.com.cn.  I just wanted to double check that wangsn1206@gmail.com is the contact email address you'd like associated with these Logs?
Hi,thanks for your comments.I am Xiu Lei with GDCA, the reason we put an gmail address is because our corporate email ocasionally blocks e-mails from overseas previously,which has now been fixed, therefore, we would like to update our contact information as follows:

  - Log Operator: GDCA
  - Email: capoc@gdca.com.cn
  - Telephone: +86(20)83487228-864
  - Authorized Personnel: Xiu Lei


Many Thanks!
Thank you for your request, we have started monitoring your Log server.
Should no issues be detected, the initial compliance monitoring phase
will be complete on August 13th 2018 and we will update this bug
shortly after that date to confirm.
Labels: Needs-Feedback
Hello Xiu Lei,

Thank you for providing your updated contact information. Could you possibly update this request using an official @gdca.com.cn email address or reach out to me via email using an official address? We just want to ensure that this request (especially the phone number change) is coming from an official GDCA representative and it's difficult to validate this from your gmail account.
Hi Devon,

Many thanks for your comment. I understand your concern, but it seems that only a Google account (which requires a gmail address in our case) can post on this platform. I will reach out to you via our official email address (capoc@gdca.com.cn) to confirm the request. Many thanks!
Labels: -Needs-Feedback
This log has passed the initial 90 day compliance period and we will start
the process to add this to Chrome.
Owner: asymmetric@chromium.org
The log's description states: "Open acceptance policy: This log is hosted on the Google Cloud in the U.S, and accepts all roots that are enabled for the server authentication trust purpose in one or more of the Microsoft, Mozilla, Apple and Google root programs.  We will update this log's list of accepted roots from time to time in accordance with this policy."

However, at the present time only two roots are accepted by this log:

C=CN, O=GUANG DONG CERTIFICATE AUTHORITY CO.,LTD., CN=GDCA TrustAUTH R5 ROOT
C=GB, ST=London, O=Google UK Ltd., OU=Certificate Transparency, CN=Merge Delay Monitor Root

Could GDCA clarify what its acceptance policy is?
Hi

Many thanks for your comments.

The acceptance policy for the GDCA CT Logs remains unchanged, our team is now working to add all the trusted root certificates in NSS and in the Apple Root Certificate Program, we will update here soon. 

Thanks.

Xiu Lei
GDCA

Hi

The accepted roots are updated, and this CT Log now accepts the certificates issued by a total of 527 root certificates. Please see the attached PEM file.

Many thanks!

Xiu Lei
GDCA

gdca-ct-trust-roots-updated.pem
1003 KB Download
Cc: certific...@googlegroups.com
As per the discusstion at: https://groups.google.com/a/chromium.org/forum/m/#!topic/ct-policy/Emh3ZaU0jqI

we would like to withdraw this inclusion application.

Thank you for your time.

Xiu Lei
GDCA
Status: WontFix (was: Assigned)
Thank you for the information; we look forward to seeing your new application.

Sign in to add a comment