Skip to content
This repository has been archived by the owner on Sep 15, 2023. It is now read-only.

Support certificates from other countries #123

Closed
ThiefMaster opened this issue Jun 20, 2021 · 7 comments
Closed

Support certificates from other countries #123

ThiefMaster opened this issue Jun 20, 2021 · 7 comments

Comments

@ThiefMaster
Copy link

When importing my German QR code it shows all the data, but also a "Certified with invalid signature" warning.

From what I understood there is a PKI with a Europe-wide root CA, so I guess it should be easily possible for the app to trust all certificates with signatures that can be tracked to that root CA.

@wglas85
Copy link

wglas85 commented Jun 21, 2021

Same happens here with an Austrian Vaccination Certificate.
Please support foreign certificates.
TIA, Wolfgang

@wglas85
Copy link

wglas85 commented Jun 23, 2021

Here is the QR code of my Austrian vaccination certificate, feel free to use it for testing purposes:
https://ecc.iteg.at/vw/COVID-19-vaccination-cert-AT-wglas.png
I will redraw this certificate from the Web Server on 2021-07-15.
This certificate is parsed and shown in the app, but "Certified with invalid signature" is shown.

@ThiefMaster
Copy link
Author

@wglas85 please don't share it, you'll have "querdenker" and similar idiots use your QR code in the hopes there aren't ID checks

@wglas85
Copy link

wglas85 commented Jun 23, 2021

If some developer downloaded the QR code, I would withdraw it from the server. And it's a temporarily valid first vaccination certificate and it's not the official PDF file...

@goebelUB
Copy link
Contributor

The apps download the list of trusted public dynamically from our backend since app version 1.2. That is, the technical infrastructure is there, so no need to post any codes. In particular, we have access to codes from other countries' test environments.

The reason that the signature verification currently fails is that we don't yet have the other countries' public keys. There is an ongoing political process to be completed before Switzerland is allowed to sync public keys with the productive European Gateway.

@ThiefMaster
Copy link
Author

I'm surprised the EU doesn't just make the public keys well... public. :D

@MDXDave
Copy link

MDXDave commented Jul 9, 2021

It's working now 😄

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants