The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key Infrastructures
Jens Hiller, Johanna Amann, Oliver Hohlfeld
摘要
Public Key Infrastructures (PKIs) with their trusted Certificate Authorities (CAs) provide the trust backbone for the Internet: CAs sign certificates which prove the identity of servers, applications, or users. To be trusted by operating systems and browsers, a CA has to undergo lengthy and costly validation processes. Alternatively, trusted CAs can cross-sign other CAs to extend their trust to them. In this paper, we systematically analyze the present and past state of cross-signing in the Web PKI. Our dataset (derived from passive TLS monitors and public CT logs) encompasses more than 7 years and 225 million certificates with 9.3 billion trust paths. We show benefits and risks of cross-signing. We discuss the difficulty of revoking trusted CA certificates where, worrisome, cross-signing can result in valid trust paths to remain after revocation; a problem for non-browser software that often blindly trusts all CA certificates and ignores revocations. However, cross-signing also enables fast bootstrapping of new CAs, e.g., Let's Encrypt, and achieves a nondisruptive user experience by providing backward compatibility. In this paper, we propose new rules and guidance for cross-signing to preserve its positive potential while mitigating its risks. CCS CONCEPTS • Security and privacy → Network security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs 等S&P 2017 · 被引用 105 次
- Where the Wild Warnings Are: Root Causes of Chrome HTTPS Certificate ErrorsMustafa Emre Acer, Emily Stark, Adrienne Porter Felt, Sascha Fahl 等CCS 2017 · 被引用 53 次
- TrustBase: An Architecture to Repair and Strengthen Certificate-based AuthenticationMark O'Neill, Scott Heidbrink, Scott Ruoti, Jordan Whitehead 等USENIX Security 2017 · 被引用 30 次
相关 Paper
- Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li 等CCS 2021 · 被引用 16 次
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford 等USENIX Security 2018 · 被引用 83 次
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric 等CCS 2019 · 被引用 138 次
- The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates 等USENIX Security 2018 · 被引用 32 次
- How Effective is Multiple-Vantage-Point Domain Control Validation?Grace H. Cimaszewski, Henry Birge-Lee, Liang Wang, Jennifer Rexford 等USENIX Security 2023
