Bug 109818 - Add AS Sertifitseerimiskeskus CA certificates to KSSL
Summary: Add AS Sertifitseerimiskeskus CA certificates to KSSL
Status: ASSIGNED
Alias: None
Product: kio
Classification: Unmaintained
Component: kssl (other bugs)
Version First Reported In: unspecified
Platform: Compiled Sources Other
: NOR wishlist
Target Milestone: ---
Assignee: Brad Hards
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-29 09:45 UTC by Peeter Russak
Modified: 2016-02-09 00:22 UTC (History)
2 users (show)

See Also:
Latest Commit:
Version Fixed/Implemented In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peeter Russak 2005-07-29 09:45:48 UTC
Version:            (using KDE Devel)
Installed from:    Compiled sources
OS:                I Don't Know

AS Sertifitseerimiskeskus ( http://www.sk.ee/pages.php/0203 ) is an issuer of Estonian national identity card's digital certificates. Also they sell site certificates for secure websites which are quite often used in Estonia because SK is most trusted CA here. It would be good to have AS Sertifitseerimiskeskus' root certificates in KSSL so they don't have to be installed separately.

Two certificates are available at page:
http://www.sk.ee/pages.php/02030102

Specific certificates needed are:
http://www.sk.ee/files/JUUR-SK.PEM.cer
http://www.sk.ee/files/KLASS3-SK.PEM.cer
Comment 1 George Staikos 2006-01-04 18:32:11 UTC
Are your certificates in any other browsers, such as MS IE or Mozilla FireFox?
Comment 2 Peeter Russak 2008-02-09 17:22:51 UTC
Those certificates are not in IE or Firefox by default, but they are added into both browsers as trusted certificates on Windows and MacOSX platforms during special software installation which enables authentication using our national identity card (client side certificate authentication using external security device). 

There's no special software installation package for Linux yet(, although recent versions of many distributions already contain every software piece needed for authentication using ID-card inside the OpenSC package). Final steps for user to do are to register PKCS#11 library inside Firefox's security devides and also add root certificates into trusted sources.

As Firefox is common for all platforms it's easy to add those certificates using descriptive documents for other platforms. IIRC Konqueror still doesn't support PKCS#11 authentication, which is sad, but at least certificates could be there already.
Comment 3 Brad Hards 2008-02-09 23:53:15 UTC
Have you asked Mozilla developers if they will include it? If so, what was the response?
Comment 4 Brad Hards 2009-06-27 06:15:43 UTC
This is pending at Mozilla (https://bugzilla.mozilla.org/show_bug.cgi?id=414520)

http://www.sk.ee/files/KLASS3-SK.PEM.cer doesn't appear to be in IE. 

$ openssl x509 -in JUUR-SK.PEM.cer -fingerprint
SHA1 Fingerprint=40:9D:4B:D9:17:B5:5C:27:B6:9B:64:CB:98:22:44:0D:CD:09:B8:89

From the Microsoft roots program (http://support.microsoft.com/kb/931125):
                 40 9d 4b d9 17 b5 5c 27 b6 9b 64 cb 98 22 44 0d cd 09 b8 89

It isn't clear the CA is actually making this request. Will follow up.

Brad
Comment 5 Brad Hards 2009-06-27 06:25:29 UTC
The JUUR-SK certificate has an appropriate key (RSA, 2048 bits) and hash (SHA-1).
Comment 6 Brad Hards 2009-06-27 06:32:43 UTC
On further investigation, it appears that the KLASS-3 certificate is an intermediate certificate, so we only need the JUUR-SK root.
Comment 7 Peeter Russak 2009-07-12 13:50:44 UTC
Some time ago already JUUR-SK was added into Windows XP throught "Root certificates update" from Windows Update. It's also mentioned here: http://support.microsoft.com/kb/931125

As I found from google Mozilla project has a recent topic from June 2009 about inclusion of Sertifitseerimiskeskus root certs. They also have a better description also about our cert system here: 
http://groups.google.com/group/mozilla.dev.security.policy/browse_thread/thread/a70a57baae77b1ee

Topic is longer there because it also contains discussion about using national identity cards as security tokens for authentication on web sites, but AFAIK KDE infrastructure doesn't support it yet.
Comment 8 Brad Hards 2010-03-08 04:34:08 UTC
Peeter,

Are you making this request as authorised representative of the CA?

Brad
Comment 9 Peeter Russak 2010-03-08 13:37:23 UTC
Hi,
I'm just a bug reporter, not a representative of CA nor connected to them. Liisa Lukin is a representative for corresponding Mozilla's bug request, maybe she can also answer your questions here. I'll send her an email.

From Mozilla's bug request:

Liisa Lukin 
AS Sertifitseerimiskeskus 
Business Development Manager
liisa.lukin@sk.ee
Comment 10 Liisa Lukin 2010-03-24 23:37:44 UTC
I'm the representative of the CA. How can I make this inclusion request official?

SK root CA (Juur-SK) is now included to MS IE and Mozilla FF and MAC OS Safari.
Comment 11 tulaclifford 2016-02-09 00:22:05 UTC
Timely comments - BTW if people require a ABC legal docs General Affidavit , my business partner filled out and esigned a sample form here http://pdf.ac/1jrPuM