'Setting Up TLS Authentication Was Hell': A Usability Study of Client Certificate Authentication
Abubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott Ruoti
Abstract
Cryptography turns a security problem into a key management problem" [1]. Despite decades of research effort towards usable key management, it remains unclear whether key management issues are inherent to every cryptographic system or merely artifacts of specific designs. To investigate, this paper presents a user study of mutual TLS (mTLS) usability, tracking 46 senior and graduate computer science students-highly technical users who configured client certificates, used them for routine authentication over a semester-long course, and managed credentials across multiple devices. Our results show that initial setup and setting up credentials on a second device are difficult, while routine authentication is easy once configured. Nevertheless, perceived usability remained low, and alarmingly, only 9% of participants fully understood mTLS security implications and key management. Our findings demonstrate that usability challenges shift across the credential lifecycle depending on system architecture. We conclude by offering design recommendations for future key management systems to better support users across the complete credential lifecycle.
• Security and privacy → Usability in security and privacy; Key management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d860ca97-904d-4f18-a3c7-ddcb3763e861Builds on16
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
- A Tale of Two Studies: The Best and Worst of YubiKey UsabilityJoshua Reynolds, Trevor Smith, Ken Reese, Luke Dickinson et al.S&P 2018 · 95 citations
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 48 citations
Related papers
- "I Can't Believe It's Not Custodial!": Usable Trustless Decentralized Key ManagementTanusree Sharma, Vivek C. Nair, Henry Wang, Yang Wang et al.CHI 2024 · 6 citations
- "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsJuliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha FahlS&P 2025
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas SchreckS&P 2026
- Exploring User-Centered Security Design for Usable Authentication CeremoniesMatthias Fassl, Lea Theresa Gröber, Katharina KrombholzCHI 2021 · 20 citations
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres et al.CCS 2019 · 46 citations
