Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

offer "baseline whitelists" for download #156

Open
adamdecaf opened this issue Feb 18, 2018 · 3 comments
Open

offer "baseline whitelists" for download #156

adamdecaf opened this issue Feb 18, 2018 · 3 comments

Comments

@adamdecaf
Copy link
Owner

As mentioned in some linked papers often CA's can be trimmed down from the top 1mil domains or similar data sets. Much larger datasets can be used as well, with perhaps a longer tail observed.

It would be handy to offer a few whitelists:

  • top 1mil
  • censys observed

https://scans.io/study/sonar.ssl
https://scans.io/study/scott-top-one-million
https://www.censys.io/data/certificates

@adamdecaf
Copy link
Owner Author

It might be easier to start with geographic whitelists in #161.

@adamdecaf adamdecaf reopened this Mar 3, 2018
@adamdecaf
Copy link
Owner Author

adamdecaf commented Mar 3, 2018

We should generate these off the top 1mil websites and maybe other scans. I haven't responded yet to my censys data request...

"You Won’t Be Needing These Any More" (Section 5) talks about how many certificates could be removed based on ZMAP scans.

For now it's probably ok to have cert-manage download these from github, but should we add a public key to verify?

https://github.com/adamdecaf/cert-manage/blob/master/docs/papers/on-removing-unused-certs.pdf

@adamdecaf adamdecaf added this to the 0.2.0 milestone Mar 3, 2018
adamdecaf added a commit that referenced this issue Mar 11, 2018
Allow them to be gzipped. Scan each columns data and use the first url
looking thing.

Issue: #156
@adamdecaf adamdecaf modified the milestones: 0.2.0, Maybe Mar 22, 2018
@adamdecaf adamdecaf changed the title baseline whitelists offer "baseline whitelists" for download Mar 22, 2018
@adamdecaf
Copy link
Owner Author

Switching to Maybe as I'm unsure the best way to distribute this.

@adamdecaf adamdecaf removed this from the Maybe milestone Mar 22, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant