Concepedia

Publication | Closed Access

Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem

16

Citations

23

References

2021

Year

Abstract

HTTPS secures communications in the web and heavily relies on the Web PKI for authentication. In the Web PKI, Certificate Authorities (CAs) are organizations that provide trust and issue digital certificates. Web clients rely on public root stores maintained by operating systems or browsers, with hundreds of audited CAs as trust anchors. However, as reported by security incidents, hidden root CAs beyond the public root programs have been imported into local root stores, which allows adversaries to gain trust from web clients.

References

YearCitations

Page 1