Skip to main content

The need of European White Knights for the TLS/SSL Certificate System

  • Conference paper
  • First Online:
ISSE 2014 Securing Electronic Business Processes
  • 838 Accesses

Abstract

Certificate Transparency ([16]), an open framework promoted by Google Inc. for monitoring and auditing SSL / TLS certificates, has a massive impact on the trust model of the internet ecosystem. As of March 2015, the implementation of this framework is required by the Internet browser Chrome for all Extended Validation Certificates (EVC-SSL). In this paper, the concepts and the structure of Certificate Transparency are explained and the impact on the existing players in the SSL / TLS ecosystem are discussed.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. E. Rescorla: SSL and TLS. Designing and building secure systems. Addison-Wesley, New York NY u. a. 2001.

    Google Scholar 

  2. OpenSSL Security Advisory vom 7. April 2014, reviewed on 30.06.2014.

    Google Scholar 

  3. K. Bhargavan, A. Delignat-Lavaud, Fournet, C., Pironti, A., and P. Strub, “Triple Handshakes and Cookie Cutters: Breaking and Fixing Authentication over TLS”, Unpublished draft , 2014.

    Google Scholar 

  4. L. A. Kaplan, O. Lendl: Zwischenbericht DigiNotar Certificate Authority Hack und Relevanz für Österreich, Cert.at. 2011.

    Google Scholar 

  5. “Report of incident on 15-MAR-2011”. Comodo group. Reviewed on 30.06.2014

    Google Scholar 

  6. T. Duong, J. Rizzo: Here Come The Ninjas, 2011. (https://bug665814.bugzilla.mozilla.org/attachment.cgi?Id=540839, reviewed on 30.06.2014).

  7. J. Ball, J.Borger, and G. Greenwald “US and UK spy agencies defeat privacy and security on the internet”. The Guardian, September 5, 2013. (http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security , reviewed on 30.06.2014)

  8. B. Beck: LibreSSL – An OpenSSL replacement. The first 30 days,and where we go from here. BSDCAN 2014. (http://www.openbsd.org/papers/bsdcan14-libressl/ , reviews on 30.06.2014.

  9. A. Langley: BoringSSL, https://www.imperialviolet.org/2014/06/20/boringssl.html und https://boringssl.googlesource.com/?format=HTML, reviewed on 30.06.2014.

  10. J. Schwenk: Sicherheit und Kryptographie im Internet. Von sicherer E-Mail bis zu IP-Verschlüsselung, herausgegeben von Vieweg+Teubner Verlag / GWV Fachverlage GmbH, Wiesbaden, 2010.

    Google Scholar 

  11. C.Eckert: IT-Sicherheit. Konzepte – Verfahren – Protokolle. 6. überarbeitete Auflage. Oldenbourg, München u. a. 2009.

    Google Scholar 

  12. A. Langley Enhancing digital certificate security, http://googleonlinesecurity.blogspot.de/2013/01/enhancing-digital-certificate-security.html, reviewed on 30.06.2014.

  13. RFC 6698 – The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

    Google Scholar 

  14. Pinning QUELLE

    Google Scholar 

  15. D. Barrett,R. Silverman,R. Byrnes: SSH, The Secure Shell: The Definitive Guide, O’Reilly & Associates, 2005.

    Google Scholar 

  16. RFC 6962 – Certificate Transparency, Experimental Request for Comments

    Google Scholar 

  17. RFC 6844 – DNS Certification Authority Authorization (CAA) Resource Record

    Google Scholar 

  18. CA/Browser Forum, https://cabforum.org/, reviewed on 30.06.2014

  19. http://www.certificate-transparency.org/ , reviewed on 30.06.2014

  20. Certificate Transparency Log Policy, https://sites.google.com/a/chromium.org/dev/Home/chromium-security/certificate-transparency/log-policy, reviewed on 30.06.2014

  21. http://www.internetworldstats.com/stats.htm, reviewed on 30.06.2014

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Arno Fiedler .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2014 Springer Fachmedien Wiesbaden

About this paper

Cite this paper

Fiedler, A., Thiel, C. (2014). The need of European White Knights for the TLS/SSL Certificate System. In: Reimer, H., Pohlmann, N., Schneider, W. (eds) ISSE 2014 Securing Electronic Business Processes. Springer Vieweg, Wiesbaden. https://doi.org/10.1007/978-3-658-06708-3_13

Download citation

  • DOI: https://doi.org/10.1007/978-3-658-06708-3_13

  • Published:

  • Publisher Name: Springer Vieweg, Wiesbaden

  • Print ISBN: 978-3-658-06707-6

  • Online ISBN: 978-3-658-06708-3

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics