Skip to main content

No Root Store Left Behind

Publication ,  Conference
Larisch, J; Aqeel, W; Chung, T; Kohler, E; Levin, D; Maggs, BM; Parno, B; Wilson, C
Published in: HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks
November 28, 2023

When a root certificate authority (CA) in the Web PKI misbehaves, primary root-store operators such as Mozilla and Google respond by distrusting that CA. However, full distrust is often too broad, so root stores often implement partial distrust of roots, such as only accepting a root for a subset of domains. Unfortunately, derivative root stores (e.g., Debian and Android) that mirror decisions made by primary root stores are often out-of-date and cannot implement partial distrust, leaving TLS applications vulnerable. We propose augmenting root stores with per-certificate programs called General Certificate Constraints (GCCs) that precisely control the trust of root certificates. We propose that primary root-store operators write GCCs and distribute them, along with routine root certificate additions and removals, to all root stores in the Web PKI. To justify our arguments, we review specific instances of CA certificate mis-issuance over the last decade that resulted in partial distrust of roots that derivative root stores were unable to precisely mirror. We also review prior work that illustrates the alarming lag between primary and derivative root stores. We discuss preliminary designs for GCC deployment and how GCCs could enable pre-emptive restrictions on CA power.

Duke Scholars

Published In

HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks

DOI

Publication Date

November 28, 2023

Start / End Page

295 / 301
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Larisch, J., Aqeel, W., Chung, T., Kohler, E., Levin, D., Maggs, B. M., … Wilson, C. (2023). No Root Store Left Behind. In HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks (pp. 295–301). https://doi.org/10.1145/3626111.3630268
Larisch, J., W. Aqeel, T. Chung, E. Kohler, D. Levin, B. M. Maggs, B. Parno, and C. Wilson. “No Root Store Left Behind.” In HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks, 295–301, 2023. https://doi.org/10.1145/3626111.3630268.
Larisch J, Aqeel W, Chung T, Kohler E, Levin D, Maggs BM, et al. No Root Store Left Behind. In: HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks. 2023. p. 295–301.
Larisch, J., et al. “No Root Store Left Behind.” HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks, 2023, pp. 295–301. Scopus, doi:10.1145/3626111.3630268.
Larisch J, Aqeel W, Chung T, Kohler E, Levin D, Maggs BM, Parno B, Wilson C. No Root Store Left Behind. HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks. 2023. p. 295–301.

Published In

HotNets 2023 - Proceedings of the 22nd ACM Workshop on Hot Topics in Networks

DOI

Publication Date

November 28, 2023

Start / End Page

295 / 301