Re: Plan to update CCADB PEM extraction tool

2018-06-04 Thread Kathleen Wilson via dev-security-policy
I would like to replace the old "Certificate ID" field with the following two fields, because they are useful in different situations, and the new field names are clear about what the values are. SPKI SHA256 Subject + SPKI SHA256 Also, I am seeing differences in the following fields for a few

Re: Plan to update CCADB PEM extraction tool

2018-06-01 Thread Ryan Sleevi via dev-security-policy
Ah, thanks! I was trying to figure out the context if it was a bug or intentional - sounds like the former, in which case, all is well :) On Fri, Jun 1, 2018 at 3:17 PM, J.C. Jones via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Ryan - > > Originally the Observatory had

Re: Plan to update CCADB PEM extraction tool

2018-06-01 Thread J.C. Jones via dev-security-policy
Ryan - Originally the Observatory had "Subject+SPKI" hash field. Someone filed a bug that Subject+SPKI field wasn't as useful for external comparisons as the SPKI, and the Observatory changed over, replacing the old Subject+SPKI hash with a pure SPKI hash. We were proposing to switch to just the

Re: Plan to update CCADB PEM extraction tool

2018-06-01 Thread Julien Vehent via dev-security-policy
I think the revert was a mistake. I should have added the SPKI instead of replacing the Subject+SPKI with SPKI. (I don't recall the discussion at the time, but I think someone confused Subject+SPKI for SPKI and I meant to address the confusion). I'll re-add the subject+spki field, this time in

Re: Plan to update CCADB PEM extraction tool

2018-06-01 Thread Ryan Sleevi via dev-security-policy
On Fri, Jun 1, 2018 at 10:20 AM, Ryan Sleevi wrote: > > > On Thu, May 31, 2018 at 6:54 PM, Kathleen Wilson via dev-security-policy < > dev-security-policy@lists.mozilla.org> wrote: > >> All, >> >> We are working towards updating the tool that we use in the CCADB to >> parse PEM data and fill in t

Re: Plan to update CCADB PEM extraction tool

2018-06-01 Thread Ryan Sleevi via dev-security-policy
On Thu, May 31, 2018 at 6:54 PM, Kathleen Wilson via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > All, > > We are working towards updating the tool that we use in the CCADB to parse > PEM data and fill in the corresponding fields in the CCADB. The new tool is > in the TLS

Plan to update CCADB PEM extraction tool

2018-05-31 Thread Kathleen Wilson via dev-security-policy
All, We are working towards updating the tool that we use in the CCADB to parse PEM data and fill in the corresponding fields in the CCADB. The new tool is in the TLS Observatory: https://github.com/mozilla/tls-observatory Example: curl https://tls-observatory.services.mozilla.com/api/v1/cer