Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
Trust-Related Activities: Internet Certification Authorities - - PowerPoint PPT Presentation
83 - Paris Trust-Related Activities: Internet Certification Authorities Revocation and SSL Replacements/Enhancements Massimiliano Pala <pala@nyu.edu> Scott Rea <Scott@DigCert.com> CRISSP NYU Poly DigiCert OpenCA Labs
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Proposal for “solving” TLS Trust Issues
▶ Revocation Information Availability
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ On-Going Work
▶ Collaborations w/ other partners from
▶ Future collaborations
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Two Main Issues in Internet Certification Authorities
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Number of compromises in 2011
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Certificate information in DNS ▶ Definition of a new DNS record (TLSA)
▶ Usage
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Web hosts to express which certifcates may be expec-
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Notary hosts to observe a server’s public key
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Sort of “Extended” Perspective
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Multiple Endorsing Certificate Authority Infrastructure
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Persistent, secure association between Internet do-
▶ Concerns
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Developing a Solution-Comparison Metrics
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Different Problems from different Perspectives
▶ Proposals
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ ICAs Best Practices
▶ OCSP as small CRLs
▶ Issues
▶ Update for RFC5019 [?]
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ DNS can be used to distribute OCSP responses
▶ Current Challenges
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Lightweight Internet Revocation Tokens
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ CA whitelisting
▶ Solutions are being discussed in CAB Forum
Massimiliano Pala <pala@nyu.edu> Research on Revocation for ICAs
83 - Paris
▶ Contacts