YoVDO

Tracking Certificate Misissuance in the Wild

Offered By: IEEE via YouTube

Tags

IEEE Symposium on Security and Privacy Courses Cybersecurity Courses Web Security Courses Certificate Authorities Courses

Course Description

Overview

Explore the systematic analysis of certificate errors in browser-trusted certificates through this IEEE Symposium on Security & Privacy presentation. Delve into the development and application of ZLint, a certificate linter that codifies CA/Browser Forum Baseline Requirements and RFC 5280 policies. Examine the drastic reduction in certificate errors since 2012, with only 0.02% of certificates containing errors in 2017. Investigate the disparity between large authorities consistently issuing correct certificates and the long tail of small authorities regularly producing non-conformant ones. Analyze the correlation between certificate errors and other types of mismanagement, as well as browser action for large authorities. Conclude by discussing how lint data can be utilized to identify authorities with concerning organizational practices and ensure the long-term health of the Web PKI.

Syllabus

Tracking Certificate Misissuance in the Wild


Taught by

IEEE Symposium on Security and Privacy

Tags

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network