draft-linus-trans-gossip-ct
Daniel Kahn Gillmor, ACLU Linus Nordberg, NORDUnet IETF93, Prague
draft-linus-trans-gossip-ct Daniel Kahn Gillmor, ACLU Linus - - PowerPoint PPT Presentation
draft-linus-trans-gossip-ct Daniel Kahn Gillmor, ACLU Linus Nordberg, NORDUnet IETF93, Prague why log accountability verifying the append-only property in space and over time changing entries not keeping the promise of an SCT
draft-linus-trans-gossip-ct
Daniel Kahn Gillmor, ACLU Linus Nordberg, NORDUnet IETF93, Prague
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
detect Log misbehavior
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
detect Log misbehavior
SCT+certs SCT+certs pollling?
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
detect Log misbehavior
SCT+certs SCT+certs pollling?
STHs STHs
STHs STHs
Monitor Auditor Browser Website
[Cert] [SCT] Timestamps Everything STH STHx,STHy Consistency Proof STH,SCT I n c l u s i
P r
Pre-cert or Cert SCT cert request cert chain + SCT SCTs HTTPS Traffic
Certificate Transparency (detect CA misbehavior)
detect Log misbehavior
SCT+certs SCT+certs pollling?
STHs STHs
STHs STHs SCT+certs