CCN-CERT (Spain)
ccn-cert-es · A · candidate
https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html
Spanish national CERT under CNI. WebFetch returns HTTP 403; bridge fetcher ALSO returns 403, Cloudflare / geo-IP gating from outside Spain or anti-bot protection. Surface as coverage gap in § 7 ('ccn-cert-es: 403 even with bridge fetcher'). NEVER demote on this transport block (Phase 5 rule A1). Retest periodically; recover if CCN-CERT publishes a CSAF feed at /.well-known/csaf/ or relaxes the geo block. | 2026-06-20 full audit (v2.well-known/csaf/ 403. Coverage gap; WebSearch-only. NEVER demote-on-transport beyond this; recover if the geo block relaxes or a CSAF feed appears. | 2026-07-05 admiralty audit: A (HIGH->A) reliability retained; national CERT authority is independent of transport. Recommend un-demote demoted->candidate: the block is a live-host 403 (geo/anti-bot), NOT a dead host/404/removed page, so per rule A1 it must not be demoted-on-transport; keep as coverage gap and recover if a CSAF feed at /.well-known/csaf/ appears or the geo block relaxes. | 2026-07-06 source_health handling: added to TRANSPORT_BLOCKED_UNREACHABLE in tools/source_health.py, direct + bridge both 403 (Cloudflare Managed-Challenge / geo-gate), so a probe 403 is now classed handled (action none, coverage gap, WebSearch substitute) instead of churning as needs-demote every sweep; still NEVER demote-on-403 (rule A1). | 2026-07-06 jina-fallback recovery: RECOVERED, fetch_method blocked -> jina. Direct fetch still 403s (geo/anti-bot), but the r.jina.ai reader proxy fetches server-side and returns the full body (39 KB, homepage + advisory pages). RECIPE: `python3 tools/fetch_source.py jina https://www.ccn-cert.cni.es/en/<path>` (or `url <path>`, which auto-falls-back to the reader). Removed from source_health TRANSPORT_BLOCKED_UNREACHABLE; it is now reachable, probes jina-ok/bridge-ok. Backup: WebSearch if the reader ever 401s. Cite the ccn-cert.cni.es page; the reader supplies the data, not the citation. | 2026-07-28: jina reader returned HTTP 402 (pooled credit exhausted) and the direct bridge returned only the navigation shell; transport block, not content death. No demotion, transport/anti-bot block, not content death. | 2026-08-03: 404 rotation priority RESOLVED. Working recipe: fetch_source.py jina on https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html (news) and .../alertas-ccn-cert.html (alerts); the old landing path 404s. Fetched 200 this run, no in-window item. | 2026-08-06: RECOVERED. The jina recipe (`jina https://www.ccn-cert.cni.es/en/updated-security/ccn-news.html`) returns a full dated news listing again, clearing the 404 recorded on the previous attempt. Kept as candidate; no in-window security content this run (latest item 2026-07-28). | 2026-08-15: health-probe failure this run is an artifact of the exhausted reader key pool, not a recipe defect; fetch_method is pinned to the reader. Not demoted; re-probe once the pool is topped up. | 2026-08-16: re-probed serially this run: the direct transport fails and the fetch falls through to the reader, where all seven keys return HTTP 402. A genuine reader-quota casualty, not a recipe defect, and a 403/quota condition never demotes. NOT demoted; recheck once reader credit is restored. | 2026-08-16 weekly: re-probed on the Spanish avisos path, the English ccn-news path and the site root, all three return nothing on the direct transport, and the reader fallback is at HTTP 402 on every key. Unchanged from the prior run's finding: a reader-credit casualty, not a recipe defect, and a quota condition never demotes. NOT demoted, fetch_method left pinned to jina because the reader is the transport that has historically worked for this host. This will keep surfacing as UNSOLVED until reader credit is restored, that is an operator item, not something to mute. | 2026-08-17: still UNSOLVED, unchanged in cause. Every direct transport returns an empty body (bridge url on the advisories listing, three candidate feed paths and the site root all returned 0 bytes this run), and the reader that historically works was credit-exhausted across all keys. Confirms the standing assessment: a reader-quota condition, not content death. NOT demoted and deliberately not muted to fetch_method: blocked, because the host is reachable the moment reader credit returns. | 2026-08-18: not attempted beyond the standing note, pinned to the exhausted reader, and this run had no home-region signal need strong enough to justify re-probing a transport already logged as failing on 2026-08-16 and 2026-08-17. No claim made about in-window content either way. | 2026-08-18: UNSOLVED flag worked this run rather than deferred: four paths probed with a desktop browser user agent (the Spanish avisos listing, the English ccn-news listing, the site root and an obrss vulnerabilities feed) and all four returned HTTP 403. This is a transport block on our egress, which never demotes, and the documented way through is the reader, which has no credit. NOT demoted and deliberately NOT muted to fetch_method blocked, because `blocked` means unreachable by every transport including the reader and the reader has not been tested this run; it has only been unaffordable. Re-test the moment reader credit returns. | 2026-08-19: HTTP 403 direct and the reader fallback exhausted; consistent with the standing egress block on this host. NOT demoted. | 2026-08-19: recipe re-confirmed correct, no change needed. Four distinct paths probed with a browser user agent (Spanish and English advisory listings, the Joomla obRSS feed route and the index.php RSS route) all returned an identical 3,354-byte HTTP 403, i.e. a whole-host edge refusal rather than a per-path problem, so no direct recipe exists to author. The health probe's needs-demote flag on this record is a consequence of the reader-credit outage, not of a broken recipe.
Cited in 0 entries
Not cited in any entry yet.