CSIRT Description for DFN-CERT
This document contains a description of DFN-CERT according to RFC 2350. It provides information about the CERT, how to contact the team, and describes its responsibilities and the services offered by DFN-CERT.
This document contains a description of DFN-CERT according to RFC 2350. It provides information about the CERT, how to contact the team, and describes its responsibilities and the services offered by DFN-CERT.
This version was published at 2024-01-26.
None.
The current version of this document can be found at: https://www.dfn-cert.de/summary/rfc-2350-csirt-description-for-dfn-cert/
This document can be retrieved from our webserver using TLS/SSL.
This section describes how to contact DFN-CERT.
DFN-CERT
DFN-CERT Services GmbH
Incident Response Team
Nagelsweg 41
D-20097 Hamburg
Germany
CET/CEST,
Central European Time or Central European Summer Time,
UTC+0100/UTC+0200
None.
Our X.509 certificate may be obtained at:
Our current PGP-Key may be obtained at:
The DFN-CERT PGP key for 2025 has the following fingerprint: 8BF2 0D6E B3E3 B04C C0F6 EED7 6D99 D2AD 3E9F 8B79
Team lead is Christine Kahl:
https://www.dfn-cert.de/unternehmen/bereiche/
General information about DFN-CERT may be found at:
The DFN.Security-Portal is available at:
https://portal.security.dfn.de/ (German)
DFN-CERT prefers to receive incident reports via e-mail. Please use our cryptographic keys above to ensure integrity and confidentiality.
We welcome automatic transfer of bulk data based on established international standards and formats. To negotiate a compatible working solution please contact the team directly before sending data automatically. This will help us to avoid any problems or issues in our tool chain, and ensures, that the data can be used in the best way possible.
DFN-CERT's hours of operation are generally restricted to regular business hours (09:00-17:00 Monday to Thursday, 09:00-16:00 on Friday) except public holidays.
Team is not reachable outside business hours. Answering machine collects calls outside business hours.
Within this section our mandate is described.
DFN-CERT's mission is to coordinate and investigate security incident response for IT-security problems at the level of the German Research Network (DFN).
Our constituency constists of the institutions that participate in the DFN.
DFN-CERT is responsible for the following autonomous systems:
28, 288, 553, 680, 1275, 1754, 2123, 2124, 2857, 5475, 5501, 5520, 8365, 8531, 9020, 12643, 12816, 13040, 16108, 20588, 20633, 28714, 29484, 34520, 34878, 41289, 41969, 42873, 43066, 47610, 50595, 56357, 58069, 60344, 60824, 199578, 200943, 205046, 207592, 215797.
DFN-CERT is the Computer Security Incident Response Team (CSIRT) for the German National Research and Educational Network (Deutsches Forschungsnetz).
Funding is provided by the DFN association (Verein zur Förderung eines Deutschen Forschungsnetzes - DFN-Verein).
DFN-CERT is a founding member of the German CERT alliance (CERT-Verbund), it is an accredited and certified TI (Trusted Introducer) team, and DFN-CERT is a full member of FIRST (Forum of Incident Response and Security Teams).
Founding member of EDUCV.
We coordinate security incidents on behalf of our constituency and at our constituents request.
This section describes our policies.
DFN-CERT addresses all kinds of security incidents which occur, or threaten to occur, within its constituency.
The level of support depends on the type and severity of the given security incident, the amount of affected institutions within our constituency, and our resources at the time.
We expect end users to contact their local systems or network administrators or their computer center.
DFN-CERT will exchange all necessary information with other CSIRTs as well as with other affected parties if they are involved in the incident or incident response process.
All information concerning one or more incidents passed on to other incident response teams, which include details about persons, organizations, IP-addresses, domain-names as well as other information revealing the identity of persons or organizations is anonymized unless explicitly stated otherwise by the persons or organizations in question. No information at all about any incident or vulnerability is given to other persons. German law enforcement personnel requesting information in the course of a criminal investigation is given the requested information within the limits of the court order and the criminal investigation, if they present a valid court order from a German court.
All e-mail postings containing official statements on behalf of the team or team members should be signed using X.509 or PGP. All e-mail containing confidential information should be encrypted and signed using X.509 or PGP. Information received in encrypted form should not be stored permanently in unencrypted form.
For sensitive information we prefer to use encrypted e-mail. For other communication phone, facsimile, postal service, or unencrypted e-mail may be used.
DFN-CERT supports the Traffic Light Protocol (TLP)
Usually our first response is timely at the same working day, if not we will respond the following working day.
Our contact information, the business hours and emergency procedure can be found in chapter 2.
This section describes the services DFN-CERT offers.
DFN-CERT coordinates all activities related to incident response within its constituency. We provide support, help, and advice with respect to the following aspects of incident management:
We do not have an incident reporting form. Please report security incidents via encrypted e-mail to cert@dfn-cert.de.
Incident reports should contain the following information:
Preferable the report includes a log file in a common format.
This document is provided 'as is' without warranty of any kind, either expressed or implied, including, but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement.
Use of this document is at the user's sole risk. All users expressly agree to this condition of use.
If you notice any mistakes within this document please send a message to us by e-mail. We will try to resolve such issues as soon as possible.