首页> 外文期刊>Computer communication review >A First Look at Certification Authority Authorization (CAA)
【24h】

A First Look at Certification Authority Authorization (CAA)

机译:认证中心授权(CAA)的初探

获取原文
获取原文并翻译 | 示例
           

摘要

Shaken by severe compromises, the Web’s Public Key Infrastructure has seen the addition of several security mechanisms over recent years. One such mechanism is the Certification Authority Authorization (CAA) DNS record, that gives domain name holders control over which Certification Authorities (CAs) may issue certificates for their domain. First defined in RFC 6844, adoption by the CA/B forum mandates that CAs validate CAA records as of September 8, 2017. The success of CAA hinges on the behavior of three actors: CAs, domain name holders, and DNS operators. We empirically study their behavior, and observe that CAs exhibit patchy adherence in issuance experiments, domain name holders configure CAA records in encouraging but error-prone ways, and only six of the 31 largest DNS operators enable customers to add CAA records. Furthermore, using historic CAA data, we uncover anomalies for already-issued certificates. We disseminated our results in the community. This has already led to specific improvements at several CAs and revocation of mis-issued certificates. Furthermore, in this work, we suggest ways to improve the security impact of CAA. To foster further improvements and to practice reproducible research, we share raw data and analysis tools.
机译:受到严重妥协的震动,近年来,Web的公钥基础结构增加了一些安全机制。一种这样的机制是证书颁发机构授权(CAA)DNS记录,它使域名持有人可以控制哪些证书颁发机构(CA)可以为其域颁发证书。 CA / B论坛首先采用RFC 6844中定义的要求,要求CA从2017年9月8日起验证CAA记录。CAA的成功取决于三个参与者的行为:CA,域名持有者和DNS运营商。我们通过经验研究它们的行为,并观察到CA在发行实验中表现出斑驳的依从性,域名持有者以令人鼓舞但容易出错的方式配置CAA记录,而31个最大的DNS运营商中只有6家允许客户添加CAA记录。此外,使用CAA的历史数据,我们可以发现已经颁发的证书的异常情况。我们在社区中传播了我们的成果。这已经导致了几个CA的特定改进,并取消了误签发的证书。此外,在这项工作中,我们提出了改善CAA安全影响的方法。为了促进进一步的改进并进行可重复的研究,我们共享原始数据和分析工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号