Title
Changing of the Guards: Certificate and Public Key Management on the Internet
Abstract
Certificates are the foundation of secure communication over the internet. However, not all certificates are created and managed in a consistent manner and the certificate authorities (CAs) issuing certificates achieve different levels of trust. Furthermore, user trust in public keys, certificates, and CAs can quickly change. Combined with the expectation of 24/7 encrypted access to websites, this quickly evolving landscape has made careful certificate management both an important and challenging problem. In this paper, we first present a novel server-side characterization of the certificate replacement (CR) relationships in the wild, including the reuse of public keys. Our data-driven CR analysis captures management biases, highlights a lack of industry standards for replacement policies, and features successful example cases and trends. Based on the characterization results we then propose an efficient solution to an important revocation problem that currently leaves web users vulnerable long after a certificate has been revoked.
Year
DOI
Venue
2022
10.1007/978-3-030-98785-5_3
PASSIVE AND ACTIVE MEASUREMENT (PAM 2022)
DocType
Volume
ISSN
Conference
13210
0302-9743
Citations 
PageRank 
References 
1
0.35
0
Authors
5
Name
Order
Citations
PageRank
Carl Magnus Bruhner110.35
Oscar Linnarsson210.35
Matus Nemec310.35
Martin Arlitt43275361.05
Niklas Carlsson558551.31