ETSI's Bug Tracker - SECURITY
View Issue Details
0007299SECURITYTSS&TPpublic14-01-2016 08:5413-12-2016 13:29
haddads 
Denis Filatov 
normalminorhave not tried
resolvedno change required 
Next Version 
Next Version 
0007299: [TP_SEC_ITSS_SND_CERT_01_02_BV] Certificate chain length ?
When can the certificate chain be longer than 2 ?

So far I have only see 3 levels for the certification ceritfication chain.
If it can be greater, longer chain should be tested.

Otherwise if the hypothesis here is the same as in ETSI TS 103 096-2 v1.1.1 should'nt we test that the chain certificate length is exactly 3 ? And that all the certificate in the chain are of version 2 ?
No tags attached.
Issue History
14-01-2016 08:54haddadsNew Issue
14-01-2016 08:54haddadsStatusnew => assigned
14-01-2016 08:54haddadsAssigned To => Denis Filatov
14-01-2016 20:52Denis FilatovNote Added: 0013689
13-12-2016 13:29Denis FilatovNote Added: 0014411
13-12-2016 13:29Denis FilatovStatusassigned => resolved
13-12-2016 13:29Denis FilatovResolutionopen => no change required

Notes
(0013689)
Denis Filatov   
14-01-2016 20:52   
Theoretically AA certificate can be issued by some other intermediate CA, the 103097 doesn't forbid it explicitly (see clause 6.3: "Root CAs, which sign certificates of other CAs, shall use the SubjectType root_ca", but it doesn't mean that all other CAs must be signed by the Root CA only). So that, chains can contain more than one AA certs and can be longer than 2 and it is necessary to support it in tests.
Actually this situation shall be avoided when possible to prevent increasing message size.
Are you agree?
(0014411)
Denis Filatov   
13-12-2016 13:29   
nothing to change for the moment. Waiting for updated specification in 103097