crocs-muni / sec-certs

Tool for analysis of security certificates and their security targets (Common Criteria, NIST FIPS140-2...).
https://sec-certs.org
MIT License
9 stars 7 forks source link

Process certificates #388

Closed J08nY closed 4 months ago

J08nY commented 4 months ago

We currently only properly process and extract data from the certification reports and security targets. Mostly that is enough, as some schemes even include the certificate in the certification report, but in some cases, important data is left in the certificate itself.

For example US and AU schemes often only have the certificate ID in the certificates and not in the report. We are thus missing their IDs. Often the certificate documents need OCR because they are scanned.

We should likely do the same for certificate as we do for the report and target, download, convert, OCR, extract metadata, extract keywords...

Example certificates: