Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin, Wei Wang, Zeyan Liu, Bingyu Li, Shushang Wen, Qiongxiao Wang, Fengjun Li
Abstract
The certificate transparency (CT) framework has been deployed to improve the accountability of the TLS certificate ecosystem. However, the current implementation of CT does not enforce or guarantee the correct behavior of third-party monitors, which are essential components of the CT framework, and raises security and reliability concerns. For example, recent studies [32], [33] reported that 5 popular third-party CT monitors cannot always return the complete set of certificates inquired by users, which fundamentally impairs the protection that CT aims to offer. This work revisits the CT design and proposes an additional component of the CT framework, CT watchers. A watcher acts as an inspector of third-party CT monitors to detect any misbehavior by inspecting the certificate search services of a third-party monitor and detecting any inconsistent results returned by multiple monitors. It also semi-automatically analyzes potential causes of the inconsistency, e.g., a monitor's misconfiguration, implementation flaws, etc. We implemented a prototype of the CT watcher and conducted a 52-day trial operation and several confirmation experiments involving 8.26M unique certificates of about 6,000 domains. From the results returned by 6 active thirdparty monitors in the wild, the prototype detected 14 potential design or implementation issues of these monitors, demonstrating its effectiveness in public inspections on third-party monitors and the potential to improve the overall reliability of CT. We revisit the CT framework design and propose a new component, called watchers, to inspect third-party monitor services. Similar to CT auditors that are tasked with detecting misbehavior on the logs, watchers are expected to detect misbehavior on third-party monitors, including faulty services and malicious actions. The watchers enable public inspections on third-party monitors and their certificate search services,
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f8e4dd6c-da3f-454f-b480-3bf6c6f8ef14Builds on9
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- Certificate Transparency in the Wild: Exploring the Reliability of MonitorsBingyu Li, Jingqiang Lin, Fengjun Li, Qiongxiao Wang et al.CCS 2019 · 45 citations
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien et al.S&P 2019 · 44 citations
Related papers
- Accountability in Certificate Transparency and VariantsTimo Treitz, Robert KünnemannCCS 2026
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta et al.NDSS 2026 · 5 citations
- Uninvited Guests: Analyzing the Identity and Behavior of Certificate Transparency BotsBrian Kondracki, Johnny So, Nick NikiforakisUSENIX Security 2022
- IKP: Turning a PKI Around with Decentralized Automated IncentivesStephanos Matsumoto, Raphael M. ReischukS&P 2017 · 168 citations
- SBDT: Search-Based Differential Testing of Certificate Parsers in SSL/TLS ImplementationsChu Chen, Pinghong Ren, Zhenhua Duan, Cong Tian et al.ISSTA 2023 · 13 citations
