Certificate Transparency - Improving Public Key Infrastructure
Talk by Emilia Käsper
Date: 04.11.13 Time: 11.00 - 12.00 Room: Y27H35/36
Transport Layer Security (TLS) is the protocol behind most of today's secure internet connections. Authenticity of those connections is guaranteed by TLS certificates issued by trusted Certification Authorities.
In July 2011, security compromise of DigiNotar, a small Dutch Certification Authority, led to a large-scale man-in-the-middle attack against users of google.com and other popular sites - but it wasn’t until more than a month later, August 28th, that a user post to Google support forums revealed the attack to the public.
Certificate Transparency is a proposed internet standard for making public TLS certificates public record. Certificate Transparency brings transparency to the public key infrastructure of TLS by making TLS certificates publicly and cryptographically auditable and holding Certification Authorities publicly accountable for certificates they issue. Thus, Certificate Transparency helps prevent and uncover man-in-the-middle attacks by making it impossible to deploy such an attack in the secret.
In this talk, I'll first cover the basics of the public key infrastructure behind TLS. I'll then introduce the concept of Certificate Transparency, explain the mechanism of cryptographically verifiable auditing in Certificate Transparency, and give an overview of the current deployment status.