Managed TLS Under Migration: Authentication Authority Across CDN and Hosting Transitions
Daniyal Ganiuly, Nurzhau Bolatbek, Assel Smaiyl

TL;DR
This paper examines how managed TLS platforms retain control over certificates during domain migrations, revealing that they continue serving old certificates until expiration, which impacts domain authentication security during transitions.
Contribution
It provides the first detailed measurement study of managed TLS behavior during provider transitions, highlighting the persistence of authentication authority with the original platform.
Findings
Platforms serve the same certificate until expiration after migration.
No new certificates are issued post-migration.
Authentication persists independently of DNS changes.
Abstract
Managed TLS has become a common approach for deploying HTTPS, with platforms generating and storing private keys and automating certificate issuance on behalf of domain operators. This model simplifies operational management but shifts control of authentication material from the domain owner to the platform. The implications of this shift during provider transitions remain insufficiently examined. This study investigates how managed TLS platforms behave when a domain is moved away from the platform that originally issued and stored its certificate. A controlled measurement environment was used to monitor multiple platforms after migration. Each platform was observed for the full remaining lifetime of the certificate that had been active during delegation. The measurements show that platforms continue to serve the same certificate until it expires, even after DNS resolvers direct traffic…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIPv6, Mobility, Handover, Networks, Security · Network Traffic and Congestion Control · Internet Traffic Analysis and Secure E-voting
