denysvitali / covid-cert-analysis

Other
148 stars 56 forks source link

Removed certificates that were found to be not issued by proper authority #10

Closed Jakub-KK closed 2 years ago

Jakub-KK commented 2 years ago

001: the same data as in https://github.com/eu-digital-green-certificates/dcc-quality-assurance/blob/main/PL/1.0.0/VAC.png but signed using different key (KID GO0rf1TneQQ= instead of KID CFUoOhVtOgo=, both appear in this issue https://github.com/eu-digital-green-certificates/dgc-testdata/issues/323 which would point to possibility of both being used to sign test DCCs) 003: the same as in commit 295b839536cc6c82162ec908fb17ca3147c592db which is assumed to be fraudulently issued 018: malformed DCC data but parsable, obviously bogus, signed using key associated with Uruguay DCC implementation (KID zqxM0w3JrYc=, see https://sizeof.cat/post/private-keys-sign-eu-greenpass-leaked/) 019: signed using key with KID Rjene8QvRwA= which is used in https://github.pathcheck.org/eu.dgc.html signing utility (part of https://github.com/vitorpamplona/vaccine-certificate-qrcode-generator project)

denysvitali commented 2 years ago

Thanks!

Jakub-KK commented 2 years ago

What do you think about removing others that are:

The 023 one gives signature error because the public key is not available now, but one can still find and use it manually, I think the key is revoked (or maybe it could be a test DCC), I don't know history of Austria DCC implementation. KID 2Rk3X8HntrI= or d919375fc1e7b6b2, country Austria with x,y=add55cf5ad1b96d47a8e6d413d3037bb473224d60ab85d6e464f21ee1d38f970,5127d9181edfbfa120d7c2659728ce9c1029dc9aa68acf50fd5313b516974177

denysvitali commented 2 years ago

Sure! It would be nice to only keep real leaks here :)