preprint Open access

The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice\n in Public Key Infrastructures

  • arXiv (Cornell University)
  • Cornell University
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Abstract

Public Key Infrastructures (PKIs) with their trusted Certificate Authorities\n(CAs) provide the trust backbone for the Internet: CAs sign certificates which\nprove the identity of servers, applications, or users. To be trusted by\noperating systems and browsers, a CA has to undergo lengthy and costly\nvalidation processes. Alternatively, trusted CAs can cross-sign other CAs to\nextend their trust to them. In this paper, we systematically analyze the\npresent and past state of cross-signing in the Web PKI. Our dataset (derived\nfrom passive TLS monitors and public CT logs) encompasses more than 7 years and\n225 million certificates with 9.3 billion trust paths. We show benefits and\nrisks of cross-signing. We discuss the difficulty of revoking trusted CA\ncertificates where, worrisome, cross-signing can result in valid trust paths to\nremain after revocation; a problem for non-browser software that often blindly\ntrusts all CA certificates and ignores revocations. However, cross-signing also\nenables fast bootstrapping of new CAs, e.g., Let's Encrypt, and achieves a\nnon-disruptive user experience by providing backward compatibility. In this\npaper, we propose new rules and guidance for cross-signing to preserve its\npositive potential while mitigating its risks.\n

Record transparency

Publication details

DOI
10.48550/arxiv.2009.08772
OpenAlex
W4287665050
Document type
preprint
Language
EN
Source
arXiv (Cornell University)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.