Measurement and Analysis of Automated Certificate Reissuance

Measurement and Analysis of Automated Certificate Reissuance
复制标题

自动证书补发的测量与分析

DOI:
10.1007/978-3-030-72582-2_10
复制
发表时间:
2021
期刊:
Proceedings of the Passive and Active Measurement Conference
影响因子:
--
通讯作者:
Olamide Omolola, Richard Roberts
Olamide Omolola, Richard Roberts
中科院分区:
--
文献类型:
--
作者:
Olamide Omolola, Richard Roberts

文献摘要

参考文献

被引文献

相似文献

传输层安全(TLS)公钥基础设施(PKI)对互联网上用户的安全和隐私至关重要。尽管TLS PKI很重要,但2010年代中期之前的工作表明,TLS PKI的管理不善往往会导致安全保障减弱,例如受损的证书未被撤销,许多互联网设备生成自签名证书。其中许多问题可以追溯到手动过程,这是当时唯一的选择。然而,在这期间的几年里,TLS PKI经历了几个变化:曾经昂贵的TLS证书现在可以免费获得,他们可以通过自动程序获得和重新颁发。在本文中,我们研究这些变化是否TLS PKI已导致PKI的管理改进。我们收集过去四年来Let's Encrypt(目前是最大的证书颁发机构)颁发的所有证书的数据。我们的分析集中在两个关键问题上:第一,管理员是否正确使用了现代CA提供的证书重新颁发自动化?我们发现,对于具有足够长的重新颁发历史的证书,其中80%确实在可预测的时间表上重新颁发了证书,这表明剩余的20%可能会使用手动流程重新颁发,尽管有许多自动化工具可以这样做。第二,使用自动化CA的管理员是否对大规模的危害做出更负责任的反应?为了回答这个问题,我们使用最近的Let's Encrypt misissuance bug作为自然实验,并发现与以前的bug相比,管理员及时重新颁发证书的比例明显更大。
The Transport Layer Security (TLS) Public Key Infrastructure (PKI) is essential to the security and privacy of users on the Internet. Despite its importance, prior work from the mid-2010s has shown that mismanagement of the TLS PKI often led to weakened security guarantees, such as compromised certificates going unrevoked and many internet devices generating self-signed certificates. Many of these problems can be traced to manual processes that were the only option at the time. However, in the intervening years, the TLS PKI has undergone several changes: once-expensive TLS certificates are now freely available, and they can be obtained and reissued via automated programs.In this paper, we examine whether these changes to the TLS PKI have led to improvements in the PKI’s management. We collect data onallcertificates issued by Let’s Encrypt (now the largest certificate authority by far) over the past four years. Our analysis focuses on two key questions: First,are administrators making proper use of the automation that modern CAs provide for certificate reissuance?We find that for certificates with a sufficiently long history of being reissued, 80% of them did reissue their certificates on a predictable schedule, suggesting that the remaining 20% may use manual processes to reissue, despite numerous automated tools for doing so. Second,do administrators that use automated CAs react to large-scale compromises more responsibly?To answer this, we use a recent Let’s Encrypt misissuance bug as a natural experiment, and find that a significantly larger fraction of administrators reissued their certificates in a timely fashion compared to previous bugs.
初步了解证书颁发机构授权 (CAA)
DOI: --
发表时间: 2018
期刊: CCRV
影响因子: --
作者:
Quirin Scheitle;Taejoong Chung;Jens Hiller;Oliver Gasser;Johannes Naab;R. V. Rijswijk;O. Hohlfeld;Ralph Holz;D. Choffnes;A. Mislove;G. Carle
通讯作者: G. Carle