Articulo de referencia

China Internet Network Information Center

The China Internet Network Information Center ( CNNIC ; 中国互联网络信息中心 ) is a public institution affiliated with the Ministry of Industry and Information Technology . [ 1 ] Founded ...

The China Internet Network Information Center (CNNIC; 中国互联网络信息中心) is a public institution affiliated with the Ministry of Industry and Information Technology.[1] Founded on 3 June 1997 and based in Zhongguancun, Beijing, the center manages the country code top-level domain name of the People's Republic of China, namely the .cn domain name.[1]

Responsibility areas

Domain name registry service

CNNIC is responsible for operating and administering China's domain name registry. CNNIC manages both the ".cn" country code top level domain and the Chinese domain name system (internationalized domain names that contain Chinese characters). As of April 2017, the total number of Chinese domain names was about 21 million.

As of January 2017, CNNIC only opened the CN domain to registered businesses,[2] required supporting documentations for domain registration such as business license or personal ID, and suspended overseas registrars even for domestic registrants.[3] CNNIC denied that it mandated existing personal domain names to be transferred to businesses.[4]Trend Micro suggested this move was still not enough to stop modern security threats from the .cn domain.[5]

IP address and Autonomous System number (AS number) allocation service

CNNIC allocates Internet Protocol (IP) addresses and AS Numbers to domestic Internet service providers and users. CNNIC is a National Internet Registry (NIR) acknowledged by the Asia-Pacific Network Information Center (APNIC). In late 2004 CNNIC launched an "IP Allocation Alliance" which simplified the procedures for obtaining IP addresses.[6]

Catalogue Database Service

CNNIC is responsible for the creation and maintenance of the state top-level network catalog database. This database provides information on Internet users, web addresses, domain names, and AS numbers.

Technical research on Internet addressing

CNNIC conducts technical research and undertakes state technical projects based on its administrative and practical network technology experience.

Internet survey and statistics

CNNIC has conducted, and continues to conduct, surveys of Internet information resources. CNNIC maintains statistics on topics such as Internet bandwidth in China, Domain Name registrations, and Internet Development in China.[7]

International liaison and policy research

As the national Network Information Center (NIC), CNNIC maintains cooperative relationships with other International Internet Communities, and works closely with NICs of other countries.

Secretariat of the Internet Policy and Resource Committee, Internet Society of China (ISC)

CNNIC serves as the Secretariat of the Internet Society of China's Internet Policy and Resource Committee. The Policy and Resource committee is in charge of tasks such as providing policy and legislation oriented suggestions to promote the growth of China's internet, facilitating the development and application of Internet resources and relevant technologies, and actively participating in the research work of domestic Internet development and administration policies.

Secretariat of the Anti-Phishing Alliance of China (APAC)

In July 2008, a broad alliance of Chinese online commerce stakeholders, including CNNIC, all major Chinese commercial banks and web hosting companies, founded the Anti-Phishing Alliance of China (APAC) in order to tackle phishing activities that abuse .cn sub-domain names. CNNIC also functions as the secretariat of APAC.[8][9]

Certificate issuance violations

In 2015, Google discovered that CNNIC had issued an intermediate CA certificate to an Egypt-based firm that used CNNIC's keys to impersonate Google domains. Google responded by removing CNNIC's root certificate from the certificate store in Google Chrome and all of Google's products.[10]

As one of the parties involved in the incident, Google stating that

Como resultado de una investigación conjunta de los sucesos relacionados con este incidente, realizada por Google y CNNIC, hemos decidido que las CA raíz y EV de CNNIC ya no serán reconocidas en los productos de Google. Esto entrará en vigor en una futura actualización de Chrome. Para ayudar a los clientes afectados por esta decisión, durante un tiempo limitado permitiremos que los certificados existentes de CNNIC sigan marcados como de confianza en Chrome, mediante el uso de una lista blanca divulgada públicamente. Si bien ni nosotros ni CNNIC creemos que se hayan emitido más certificados digitales no autorizados, ni creemos que los certificados emitidos erróneamente se hayan utilizado fuera del ámbito limitado de la red de pruebas de MCS Holdings, CNNIC trabajará para prevenir futuros incidentes. CNNIC implementará la Transparencia de Certificados para todos sus certificados antes de cualquier solicitud de reinclusión. Felicitamos a CNNIC por sus medidas proactivas y les invitamos a volver a solicitar la reinclusión una vez que se hayan implementado los controles técnicos y de procedimiento adecuados. [ 11 ]

Mozilla respondió al incidente, declarando que

"El equipo de CA de Mozilla considera que las acciones de CNNIC constituyen un comportamiento reprobable, y las infracciones de la política son más graves que las de incidentes anteriores. La decisión de CNNIC de infringir su propia Declaración de Prácticas de Certificación es especialmente grave y suscita inquietudes que van más allá del alcance inmediato del certificado intermedio emitido erróneamente. Tras un debate público... planeamos modificar el código de validación de certificados de Firefox para que rechace cualquier certificado emitido por una raíz de CNNIC con una fecha de caducidad igual o posterior al 1 de abril de 2015." [ 12 ]

Referencias

  1. ^ "关于我们 - CNNIC" . CNNICO . Consultado el 27 de septiembre de 2024 .{{cite web}}: CS1 maint: servicio de archivado obsoleto ( enlace )
  2. Lafraniere, Sharon (17 de diciembre de 2009). "China impone nuevos controles de Internet" . The New York Times . Archivado del original el 7 de noviembre de 2015. Consultado el 24 de febrero de 2017 .
  3. "CNNIC suspende indefinidamente los nuevos registros extranjeros .CN" . Archivado del original el 15 de enero de 2010. Consultado el 7 de enero de 2010 .
  4. ^ "传CN个人域名须转公司名下 CNNIC收紧域名审核" . Archivado desde el original el 13 de enero de 2010 . Consultado el 7 de enero de 2010 .
  5. "Aviso de Trend Micro sobre los requisitos de registro de dominios de CNNIC" . Consultado el 1 de febrero de 2010 .{{cite web}}: CS1 maint: servicio de archivado obsoleto ( enlace )
  6. "CNNIC proporcionará procedimientos más sencillos para la asignación de direcciones IP" . 23 de diciembre de 2004. Archivado del original el 1 de octubre de 2008. Consultado el 11 de mayo de 2008 .
  7. Estadísticas de Internet de CNNIC archivadas el 16 de mayo de 2008 en Wayback Machine
  8. "Resolución para detener los sitios de phishing .CN" . Archivado del original el 22 de agosto de 2008. Consultado el 24 de julio de 2008 .{{cite journal}}: Para citar una revista se requiere |journal=( ayuda )
  9. "China forma una alianza contra el phishing" . Blog.anta.net . 24 de julio de 2008. ISSN 1797-1993 . Consultado el 24 de julio de 2008 . {{cite journal}}: CS1 maint: servicio de archivado obsoleto ( enlace )
  10. "Blog de seguridad en línea de Google: Manteniendo la seguridad de los certificados digitales" . Googleonlinesecurity.blogspot.se. 23 de marzo de 2015. Archivado del original el 7 de marzo de 2016. Consultado el 1 de marzo de 2020 .
  11. "Blog de seguridad en línea de Google: Manteniendo la seguridad de los certificados digitales" . Googleonlinesecurity.blogspot.se. 23 de marzo de 2015. Archivado del original el 7 de marzo de 2016. Consultado el 1 de marzo de 2020 .
  12. El incidente MCS y sus consecuencias para CNNIC Archivado el 3 de abril de 2015 en Wayback Machine 2.3. Desconfianza en los nuevos certificados CNNIC Mozilla 1 de abril de 2015, pág. 9.
  • Sitio web oficialEdita esto en Wikidata