Characterizing the Root Landscape of Certificate Transparency Logs
Nikita Korzhitskii, Niklas Carlsson

TL;DR
This paper analyzes the evolving landscape of root stores in Certificate Transparency logs, comparing them to major software vendors, and investigates how root store management impacts log behavior and security.
Contribution
It provides the first comprehensive characterization of CT root stores, introduces a new analysis tool, and examines the relationship between root store management and log integrity.
Findings
CT logs maintain their own root lists and show evolving policies.
Root store mismanagement may be linked to log misbehavior.
Survey results reveal operator perspectives on CT log policies.
Abstract
Internet security and privacy stand on the trustworthiness of public certificates signed by Certificate Authorities (CAs). However, software products do not trust the same CAs and therefore maintain different root stores, each typically containing hundreds of trusted roots capable of issuing "trusted" certificates for any domain. Incidents with misissued certificates motivated Google to implement and enforce Certificate Transparency (CT). CT logs archive certificates in a public, auditable and append-only manner. The adoption of CT changed the trust landscape. As a part of this change, CT logs started to maintain their own root lists and log certificates that chain back to one of the trusted roots. In this paper, we present the first characterization of this emerging CT root store landscape, as well as the tool that we developed for data collection, visualization, and analysis of the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Access Control and Trust
