GithubHelp home page GithubHelp logo

eu-digital-green-certificates / dcc-quality-assurance Goto Github PK

View Code? Open in Web Editor NEW
36.0 36.0 131.0 40.53 MB

This repository contains a curated selection of verified testdata.

License: Apache License 2.0

Python 100.00%

dcc-quality-assurance's People

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

dcc-quality-assurance's Issues

SpecialCaseHandling

SpecialCaseHandling.md needs review and correcting on some points, primarily regarding Verifier and Issuer actions.

CI Script: Strict Schema Validation

The Script should load from a subfolder all Schemas and should check this schema against the QR code and the embedded version number. If the schema is not fullfilled, the codes are returned. E.g. fnt: "Ärmel" --> fails because [A-Z>]$ is allowed

CI Script: EXP in Recoveries

The EXP field must be checked in the recovery statement against the validUntil field. The validuntil field must be greater /equal than EXP date. In some codes there are validuntil fields e.g. to 17.6.2021 but EXP is 2022.

[GB>SCT] Invalid date format

During some automated tests, we've discovered an issue with new certificates from Scotland.
@andrewkay18981 you've added new certificates, but these seem to have an invalid date format
GB/1.3.0/TEST_SCT.png has a date '2022-01-31T05:00:00+0'

According to the ISO specification (https://en.wikipedia.org/wiki/ISO_8601), you need to have 2 numbers behind the +

<time>Z
--
<time>±hh:mm
<time>±hhmm
<time>±hh

This results in an error thrown in our validation app, causing these certificates to be marked as invalid, even though they may be valid. Can you confirm the production certificates of Scotland don't all contain this invalid format? If so, we'll have to add a workaround on our side and other countries may block these codes accidentally.

QRs that do not conform to the regulation are not labeled

In merge #148 we're merging Qr's that do not meet the Regulation (extra PII, such as passport number and Sex).

May be wise to either mark them thus - or have a separate folder that says 'in-compliant certs for testing'. As to avoid that implementors make a mistaken assumption.

CI Enhancement

To avoid the upload of productive certificates, the CI in QA and testdata should be enhanced by checking the prod keys.

EU DCC iat exp values

we scanned an ES country , EU DCC code
we are getting
iat 2021-07-20 07:33:17 and
exp 2021-08-19 07:33:17
for vaccination
is it an valid values ?
in ES country, EU DCC vaccination is valid for only one month ?

QRs of SG render badly

There seems to be an aliasing artefact in the SG Qr coes from PR#157:

Enlarged example:

Screenshot 2021-09-03 at 14 21 20

148.

spanish certificates not validating with the android app

Got two spanish certificates, one from the reginal (valencia) authority and another one from the spanish government.

both are giving "failed" in the android app verification.

Decoding manually the CBOR records, in the "valencian" one, can see a difference in the "6" field. In this certificates, they used a decimal point in the expiration date.
{
"1": "ES",
"4": 1685271300,
"6": 1624617519.261,

Also i have a problem verifying the signature:

KeyError: 'Key ID not found in cert list: 65c7e496812f7c64'

decoding the "spanish" one, the timestamp is OK, but i get an error:

Key ID not found in cert list: a85345d9d0be9a34

may be there is some problem with the signing keys in the gateway? If you need the png or pdf, let me know how to send it to you.

PS. Related issues are in:

eu-digital-green-certificates/dgca-verifier-app-android#94

and
eu-digital-green-certificates/dgca-verifier-app-android#116

IE: Vaccination certificate dosage values contain float values

Since the 20th of August, we're getting helpdesk reports that turn out to be float values in the dosage numbers of IE vaccination DCCs. This issue has been reported to the Ireland team on the same day. Since we're getting a lot of reports (also public) about this issue, we're moving to allow whole-number float values in our verifier application (so 1.0, but not 1.5 or 1.0001).

  1. Can this case be reproduced with acceptance keys and added to SpecialCaseHandling.md so it can be checked by other member states.
  2. We're assuming the dosage floats are always whole numbers, i.e. 1.0 / 1.0, and never something like 1.5 / 1.0 or 1.0001 / 1.0. Is that right?
  3. What is the timeline on getting this fixed on the issuer side?

I only have production examples, which I can't share here, so I've recreated the scenario with the NL signer and NL acceptance keys (IE CWT issuer due to details on our side):



We've done testing on other verifier apps, with these results:

- NL CC: ❌ (invalid QR)
- NL DCC: ❌ (invalid QR)
- BE: ❌ (format not recognized)
- CH: ❌ (format invalid)
- LU: ✅❌ (parses as 1/1, but invalid code IE en invalid code vaccine, maybe config problem)
- IT: ✅
- CZ: ❌ (unable to recognize QR format)
- DK: ✅
- AT: ❌ (Ihr certifikat ist zeitlich abgelaufen / fehler VA3)
- FR: ✅
- HU: ✅
- PT: ✅
- LV: ✅

Could countries who accept these QRs with float dosage values indicate how they handle this case? Are you casting, flooring, rounding?

test data for FR

can you provide some valid test data that passes the TACVerif ? thank you

Bulgarian certificates verification problem

Bulgarian vaccination certificate cannot be verified using app (Android 'tst' and 'acc' releases, tested using all versions up to 1.1.5). Recently (July 4) all certificates of vaccination issued by the Bulgarian government to those vaccinated with the Pfizer/BioNTech and the Moderna vaccines were reissued, apparently due to a mistake in the 'Manufacturer' field in both vaccines. Still, neither my old certificate, nor my new one, are read correctly by the app - I get the "Verification invalid" message.

Production vaccination certificates for UY (Uruguay) seem not to have proper format

Hi, I don't know if this belongs here but any help would be appreciated.
We have received a complaint from a citizen of Uruguay saying that his certificate is not validated by the official verifier app of the Government of Catalonia.

Uruguay has a valid public key in the Trusted List (kid="woowbyJtRFo="), and the certificate of the citizen is correctly signed by the corresponding private key.
However, the format of the certificate seems incorrect, as instead of the fields "ver" and "dob" and structures "nam" and "v", the certificate has the fields "Date", "Name", "CountryCode", "DocumentType", "DocumentNumber" an a structure "VaccinationInfo".

I tend to think that this is an invalid certificate, but given that it is correctly signed by the private key of Uruguay (as I said, the public key is in the official Trusted List), I wonder if anybody has encountered something similar.

By the way, the test certificate in this repository has the correct format, so it seems a problem related to issuance in production. As additional information, the issuance date of the incorrect certificate is December 28th.

Do you have any reccommendations on this subject?
Thanks in advance,
Jesus Ruiz

Austrian certificates not validating in android App

As asked to by @kerstin-oppermann-tsi in this issue I will also create an issue here (for details see other issue). Here just a short sum up:

Test- and vaccination certificates issued by the austrian government cannot be validated in the android app because of a signature error. Ie, the necessary information (name, test- or vaccination date, ...) can be sucessfully extracted from the QR Code. But when trying to validate the signature, no certificate is found for the keyid, thus the test- or vaccination certificate is flagged as invalid.

The signature of both certificates can be validated in the offical webapp of the austrian government "https://qr.gv.at" using the following certificate

-----BEGIN CERTIFICATE-----
MIIB7zCCAZagAwIBAgIKAXnM+L47fmBcezAKBggqhkjOPQQDAjBEMQswCQYDVQQG
EwJBVDEPMA0GA1UECgwGQk1TR1BLMQwwCgYDVQQFEwMwMDExFjAUBgNVBAMMDUFU
IERHQyBDU0NBIDEwHhcNMjEwNjAyMTM0NTI0WhcNMjMwNjAyMTM0NTI0WjBGMQsw
CQYDVQQGEwJBVDEPMA0GA1UECgwGQk1TR1BLMQ8wDQYDVQQFEwYwMDEwMDExFTAT
BgNVBAMMDEFUIERHQyBEU0MgMTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABGBN
uKiCpnXH0VlIdk6pJZH2ep8jQaV+FR3izMXxZfK5EPGZLtG3Jx+TmV3JJErfrSrP
hRmfbSidVbTQ5nnZS+ujbjBsMA4GA1UdDwEB/wQEAwIHgDAdBgNVHQ4EFgQUNs2s
mrjBhuR5Bqxl6teE1x1o2ycwHwYDVR0jBBgwFoAUHyKsHGUWKbTBmLNjb7/dCZ27
e3swGgYDVR0QBBMwEYEPMjAyMTEyMTYxNDQ1MjRaMAoGCCqGSM49BAMCA0cAMEQC
IDjXHnyzq3sTisMX1uY8xQ2ZqCRL2xmxtYOPhSZ9ZacYAiAqHUMOC7WNgq4h28n3
1WLc1mMPAYauWslSEwnXC79AGw==
-----END CERTIFICATE-----

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.