The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice\n in Public Key Infrastructures
At a glance
- Citations
- 0
- References
- 0
- Comments
- 0
Abstract
Public Key Infrastructures (PKIs) with their trusted Certificate Authorities\n(CAs) provide the trust backbone for the Internet: CAs sign certificates which\nprove the identity of servers, applications, or users. To be trusted by\noperating systems and browsers, a CA has to undergo lengthy and costly\nvalidation processes. Alternatively, trusted CAs can cross-sign other CAs to\nextend their trust to them. In this paper, we systematically analyze the\npresent and past state of cross-signing in the Web PKI. Our dataset (derived\nfrom passive TLS monitors and public CT logs) encompasses more than 7 years and\n225 million certificates with 9.3 billion trust paths. We show benefits and\nrisks of cross-signing. We discuss the difficulty of revoking trusted CA\ncertificates where, worrisome, cross-signing can result in valid trust paths to\nremain after revocation; a problem for non-browser software that often blindly\ntrusts all CA certificates and ignores revocations. However, cross-signing also\nenables fast bootstrapping of new CAs, e.g., Let's Encrypt, and achieves a\nnon-disruptive user experience by providing backward compatibility. In this\npaper, we propose new rules and guidance for cross-signing to preserve its\npositive potential while mitigating its risks.\n
Publication details
- DOI
- 10.48550/arxiv.2009.08772
- OpenAlex
- W4287665050
- Document type
- preprint
- Language
- EN
- Source
- arXiv (Cornell University)
- Last metadata update
Comments
Log in to join the discussion.