Proceedings 2014 Network and Distributed System Security Symposium 2014
DOI: 10.14722/ndss.2014.23305
|View full text |Cite
|
Sign up to set email alerts
|

Web PKI: Closing the Gap between Guidelines and Practices

Abstract: Abstract-A string of recent attacks against the global public key infrastructure (PKI) has brought to light weaknesses in the certification authority (CA) system. In response, the CA/Browser Forum, a consortium of certification authorities and browser vendors, published in 2011 a set of requirements applicable to all certificates intended for use on the Web and issued after July 1st, 2012, following the successful adoption of the extended validation guidelines in 2007. We evaluate the actual level of adherence… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

1
18
0

Year Published

2014
2014
2024
2024

Publication Types

Select...
3
3
2

Relationship

2
6

Authors

Journals

citations
Cited by 27 publications
(19 citation statements)
references
References 14 publications
(11 reference statements)
1
18
0
Order By: Relevance
“…Large-scale surveys of SSL certificates “in the wild” can be found in [19, 25, 27, 78]. Because their objective is to collect and analyze certificates, not to find certificate validation errors in SSL/TLS implementations, they are complementary to this paper: for example, their certificate corpi can be used to “seed” frankencert generation (Section VII).…”
Section: Related Workmentioning
confidence: 99%
“…Large-scale surveys of SSL certificates “in the wild” can be found in [19, 25, 27, 78]. Because their objective is to collect and analyze certificates, not to find certificate validation errors in SSL/TLS implementations, they are complementary to this paper: for example, their certificate corpi can be used to “seed” frankencert generation (Section VII).…”
Section: Related Workmentioning
confidence: 99%
“…We assume a rough upper bound of 10 million certificates [6] each representing a unique domain name, though this number will likely be much less since DSFs are only intended to be used during the deployment process. Then for a 1% false positive rate the size of a DSF should be at most 13 MB, which is well below the storage limit of modern client machines.…”
Section: Benefitsmentioning
confidence: 99%
“…We can easily build statistics about the number of domains found in publicly trusted certificates issued between July 2012 and July 2013 based on data collected in [9]. The results, depicted in Figure 6, show that about 40% of issued certificates are valid for a single domain; however, about 10% of them contain a wildcard.…”
Section: Multi-domain Certificatesmentioning
confidence: 99%
“…It is tempting to argue that the fact these domains appear in the same certificate is a clue that their sharing of some TLS session-specific attributes could be acceptable, but we stress that it is in fact not the case. For instance, recall from Section 2 that CloudFlare uses shared certificates that cover dozens of customers' domains [9,35]. In fact, it is common on today's web to connect to a website whose certificate is shared with a malicious, attacker-controlled domain.…”
Section: Connection Sharing In Spdy and Http/2mentioning
confidence: 99%
See 1 more Smart Citation