crtsh / certwatch_db

Database schema
https://crt.sh/
GNU General Public License v3.0
196 stars 36 forks source link

Filter by Mozilla Owner #28

Open benwilsonusa opened 7 years ago

benwilsonusa commented 7 years ago

For compliance purposes, it would be very handy to be able to filter all of a CA Owner's CAs based on the "Mozilla Owner" field (i.e. the way that the CCADB tracks CA compliance). For instance, Digicert acquired some Cybertrust CAs from Verizon, so the Issuer "O" field is not as useful for obtaining a comprehensive snapshot. If I could see all of them on one screen, then it would be easier for me to remediate issues with external Sub CAs that issue non-compliant certificates.

dougbeattie commented 5 years ago

GlobalSign has some CAs like this also and it would help if they were categorized as "GlobalSign Operated" CAs. In our case, the SSL certificates will have pointers to GlobalSign in the Certificate Policies extension as well as the URLs in AIA and CDP. If these point to GlobalSign policies or URLs, then they could be categorized as being operated by GlobalSign.