ctipilot.ch

CCN-CERT (Spain)

ccn-cert-es · A · candidate

https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html

ch-eugovlang: eslang: enfetch failures: 0quiet periods: 0last fetch: 2026-08-06

Spanish national CERT under CNI. WebFetch returns HTTP 403; bridge fetcher ALSO returns 403 — Cloudflare / geo-IP gating from outside Spain or anti-bot protection. Surface as coverage gap in § 7 ('ccn-cert-es: 403 even with bridge fetcher'). NEVER demote on this transport block (Phase 5 rule A1). Retest periodically; recover if CCN-CERT publishes a CSAF feed at /.well-known/csaf/ or relaxes the geo block. | 2026-06-20 full audit (v2.well-known/csaf/ 403. Coverage gap; WebSearch-only. NEVER demote-on-transport beyond this; recover if the geo block relaxes or a CSAF feed appears. | 2026-07-05 admiralty audit: A (HIGH->A) reliability retained — national CERT authority is independent of transport. Recommend un-demote demoted->candidate: the block is a live-host 403 (geo/anti-bot), NOT a dead host/404/removed page, so per rule A1 it must not be demoted-on-transport; keep as coverage gap and recover if a CSAF feed at /.well-known/csaf/ appears or the geo block relaxes. | 2026-07-06 source_health handling: added to TRANSPORT_BLOCKED_UNREACHABLE in tools/source_health.py — direct + bridge both 403 (Cloudflare Managed-Challenge / geo-gate), so a probe 403 is now classed handled (action none, coverage gap, WebSearch substitute) instead of churning as needs-demote every sweep; still NEVER demote-on-403 (rule A1). | 2026-07-06 jina-fallback recovery: RECOVERED — fetch_method blocked -> jina. Direct fetch still 403s (geo/anti-bot), but the r.jina.ai reader proxy fetches server-side and returns the full body (39 KB, homepage + advisory pages). RECIPE: `python3 tools/fetch_source.py jina https://www.ccn-cert.cni.es/en/<path>` (or `url <path>`, which auto-falls-back to the reader). Removed from source_health TRANSPORT_BLOCKED_UNREACHABLE — it is now reachable, probes jina-ok/bridge-ok. Backup: WebSearch if the reader ever 401s. Cite the ccn-cert.cni.es page; the reader supplies the data, not the citation. | 2026-07-28: jina reader returned HTTP 402 (pooled credit exhausted) and the direct bridge returned only the navigation shell; transport block, not content death. No demotion — transport/anti-bot block, not content death. | 2026-08-03: 404 rotation priority RESOLVED. Working recipe: fetch_source.py jina on https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html (news) and .../alertas-ccn-cert.html (alerts); the old landing path 404s. Fetched 200 this run, no in-window item. | 2026-08-06: RECOVERED. The jina recipe (`jina https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html`) returns a full dated news listing again, clearing the 404 recorded on the previous attempt. Kept as candidate; no in-window security content this run (latest item 2026-07-28).

Cited in 0 entries

Not cited in any entry yet.