ETSI's Bug Tracker - SECURITY
View Issue Details
0007300SECURITYTSS&TPpublic14-01-2016 09:0813-12-2016 13:11
haddads 
Denis Filatov 
normalminorhave not tried
resolvedno change required 
Test_Spec_TS103096_V121 
Next Version 
0007300: [TP_SEC_ITSS_SND_CERT_02_01_BV][General remarks/questions] Testing the certifcate chain
Shouldn't we check (add a test?) that the chain is not longer than an upper 3 and that longer chains are rejected ? As far as I know the chain presented in the standards are always the same (root, AA, AT, cert), but can it be longer ?

Since validating long certification chains can be a source of attacks. If it can be longer we should add tests with long chains (10-15 certificates, 100 ?).

Also I think that the test should check the validity of the entire chain,
not just the one of the last certificate e.g. : no loop, all the certificates are valid, etc; this is not tested.
No tags attached.
Issue History
14-01-2016 09:08haddadsNew Issue
14-01-2016 09:08haddadsStatusnew => assigned
14-01-2016 09:08haddadsAssigned To => Denis Filatov
14-01-2016 10:04Peter FelberNote Added: 0013686
15-01-2016 15:27Denis FilatovNote Added: 0013698
13-12-2016 13:11Denis FilatovNote Added: 0014408
13-12-2016 13:11Denis FilatovStatusassigned => resolved
13-12-2016 13:11Denis FilatovResolutionopen => no change required

Notes
(0013686)
Peter Felber   
14-01-2016 10:04   
I didn't find a definition for the maximum length of certificate-chains in TS102940 or TS102941. If this is left open, we should also assume certificate chains which are longer than 3 certificates.
(0013698)
Denis Filatov   
15-01-2016 15:27   
Look at the figure A.2 in TS102940: there are intermediate CAs on the picture.
(0014408)
Denis Filatov   
13-12-2016 13:11   
nothing to fix