No Root Store Left Behind

dc.contributor.authorLarisch, Jamesen
dc.contributor.authorAqeel, Waqaren
dc.contributor.authorChung, Taejoongen
dc.contributor.authorKohler, Eddieen
dc.contributor.authorLevin, Daveen
dc.contributor.authorMaggs, Bruceen
dc.contributor.authorParno, Bryanen
dc.contributor.authorWilson, Christoen
dc.date.accessioned2023-12-04T18:14:00Zen
dc.date.available2023-12-04T18:14:00Zen
dc.date.issued2023-11-28en
dc.date.updated2023-12-01T08:52:09Zen
dc.description.abstractWhen a root certificate authority (CA) in the Web PKI misbehaves, primary root-store operators such as Mozilla and Google respond by distrusting that CA. However, full distrust is often too broad, so root stores often implement partial distrust of roots, such as only accepting a root for a subset of domains. Unfortunately, derivative root stores (e.g., Debian and Android) that mirror decisions made by primary root stores are often out-of-date and cannot implement partial distrust, leaving TLS applications vulnerable. We propose augmenting root stores with per-certificate programs called General Certificate Constraints (GCCs) that precisely control the trust of root certificates. We propose that primary root-store operators write GCCs and distribute them, along with routine root certificate additions and removals, to all root stores in the Web PKI. To justify our arguments, we review specific instances of CA certificate mis-issuance over the last decade that resulted in partial distrust of roots that derivative root stores were unable to precisely mirror. We also review prior work that illustrates the alarming lag between primary and derivative root stores.We discuss preliminary designs for GCC deployment and how GCCs could enable pre-emptive restrictions on CA power.en
dc.description.versionPublished versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.doihttps://doi.org/10.1145/3626111.3630268en
dc.identifier.urihttps://hdl.handle.net/10919/116723en
dc.language.isoenen
dc.publisherACMen
dc.rightsIn Copyrighten
dc.rights.holderThe author(s)en
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/en
dc.titleNo Root Store Left Behinden
dc.typeArticle - Refereeden
dc.type.dcmitypeTexten

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
3626111.3630268.pdf
Size:
464.9 KB
Format:
Adobe Portable Document Format
Description:
Published version
License bundle
Now showing 1 - 1 of 1
Name:
license.txt
Size:
1.5 KB
Format:
Item-specific license agreed upon to submission
Description: