A First Look at Certification Authority Authorization (CAA)

A First Look at Certification Authority Authorization (CAA)
复制标题

初步了解证书颁发机构授权 (CAA)

DOI:
--
复制
发表时间:
2018
期刊:
CCRV
影响因子:
--
通讯作者:
G. Carle
G. Carle
中科院分区:
--
文献类型:
--
作者:
Quirin Scheitle;Taejoong Chung;Jens Hiller;Oliver Gasser;Johannes Naab;R. V. Rijswijk;O. Hohlfeld;Ralph Holz;D. Choffnes;A. Mislove;G. Carle

文献摘要

参考文献

被引文献

相似文献

由于受到严重的危害,近年来,Web的公钥基础设施增加了几种安全机制。一种这样的机制是证书颁发机构授权(CAA)DNS记录,它使域名持有者能够控制哪些证书颁发机构(CA)可以为其域颁发证书。在RFC 6844中首次定义,CA/B论坛的采用要求CA验证CAA记录,截止日期为2017年9月8日。CAA的成功取决于三个参与者的行为:CA,域名持有者和DNS运营商。我们实证研究他们的行为,并观察到CA在发行实验中表现出不规则的坚持,域名持有人以令人鼓舞但容易出错的方式配置CAA记录,31个最大的DNS运营商中只有6个允许客户添加CAA记录。此外,使用历史CAA数据,我们发现了已经颁发的证书的异常。我们在社区中传播了我们的成果。这已经导致了几个CA的具体改进和错误颁发证书的撤销。此外,在这项工作中,我们建议如何提高CAA的安全影响。为了促进进一步的改进和实践可重复的研究,我们分享原始数据和分析工具。
Shaken by severe compromises, the Web’s Public Key Infrastructure has seen the addition of several security mechanisms over recent years. One such mechanism is the Certification Authority Authorization (CAA) DNS record, that gives domain name holders control over which Certification Authorities (CAs) may issue certificates for their domain. First defined in RFC 6844, adoption by the CA/B forum mandates that CAs validate CAA records as of September 8, 2017. The success of CAA hinges on the behavior of three actors: CAs, domain name holders, and DNS operators. We empirically study their behavior, and observe that CAs exhibit patchy adherence in issuance experiments, domain name holders configure CAA records in encouraging but error-prone ways, and only six of the 31 largest DNS operators enable customers to add CAA records. Furthermore, using historic CAA data, we uncover anomalies for already-issued certificates. We disseminated our results in the community. This has already led to specific improvements at several CAs and revocation of mis-issued certificates. Furthermore, in this work, we suggest ways to improve the security impact of CAA. To foster further improvements and to practice reproducible research, we share raw data and analysis tools.
DOI: 10.1145/3133956.3133988
发表时间: 2017-10
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis
通讯作者: T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis