GSA / data

Assorted data from the General Services Administration.
2.11k stars 275 forks source link

Create a CSV file tracking OCSP/CRL sites #180

Closed konklone closed 5 years ago

konklone commented 5 years ago

This starts a CSV file with manually marked OCSP-only or CRL-only hostnames, for those services that meet the OCSP/CRL exclusion in M-15-13 and BOD 18-01.

To start, it's a few self-reported hosts within llnl.gov.

I think it will be important to be strict about only adding services which are reserved principally for production OCSP/CRL services. Dev/staging sites that may also dual-host content, for example, would not be appropriate to add here, nor would any other service that an agency might believe merits exemption on the grounds of being unimportant or not "public-facing".

IanLee1521 commented 5 years ago

Huh.. guess I should go educate myself more on what those servers are doing...

jsf9k commented 5 years ago

Nice! I will use this in dhs-ncats/gatherer.