The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key Infrastructures
Jens Hiller, Johanna Amann, Oliver Hohlfeld
Abstract
Public Key Infrastructures (PKIs) with their trusted Certificate Authorities (CAs) provide the trust backbone for the Internet: CAs sign certificates which prove the identity of servers, applications, or users. To be trusted by operating systems and browsers, a CA has to undergo lengthy and costly validation processes. Alternatively, trusted CAs can cross-sign other CAs to extend their trust to them. In this paper, we systematically analyze the present and past state of cross-signing in the Web PKI. Our dataset (derived from passive TLS monitors and public CT logs) encompasses more than 7 years and 225 million certificates with 9.3 billion trust paths. We show benefits and risks of cross-signing. We discuss the difficulty of revoking trusted CA certificates where, worrisome, cross-signing can result in valid trust paths to remain after revocation; a problem for non-browser software that often blindly trusts all CA certificates and ignores revocations. However, cross-signing also enables fast bootstrapping of new CAs, e.g., Let's Encrypt, and achieves a nondisruptive user experience by providing backward compatibility. In this paper, we propose new rules and guidance for cross-signing to preserve its positive potential while mitigating its risks. CCS CONCEPTS • Security and privacy → Network security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3721ee6f-c8e7-406a-a6b9-12c73ce9ebbeCited by top-tier papers1
Ask how each one uses itBuilds on3
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
- Where the Wild Warnings Are: Root Causes of Chrome HTTPS Certificate ErrorsMustafa Emre Acer, Emily Stark, Adrienne Porter Felt, Sascha Fahl et al.CCS 2017 · 53 citations
- TrustBase: An Architecture to Repair and Strengthen Certificate-based AuthenticationMark O'Neill, Scott Heidbrink, Scott Ruoti, Jordan Whitehead et al.USENIX Security 2017 · 30 citations
Related papers
- Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li et al.CCS 2021 · 16 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric et al.CCS 2019 · 138 citations
- The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates et al.USENIX Security 2018 · 32 citations
- How Effective is Multiple-Vantage-Point Domain Control Validation?Grace H. Cimaszewski, Henry Birge-Lee, Liang Wang, Jennifer Rexford et al.USENIX Security 2023
