2018
DOI: 10.1145/3213232.3213235
|View full text |Cite
|
Sign up to set email alerts
|

A First Look at Certification Authority Authorization (CAA)

Abstract: Shaken by severe compromises, the Web's Public Key Infrastructure has seen the addition of several security mechanisms over recent years. One such mechanism is the Certification Authority Authorization (CAA) DNS record, that gives domain name holders control over which Certification Authorities (CAs) may issue certificates for their domain. First defined in RFC 6844, adoption by the CA/B forum mandates that CAs validate CAA records as of September 8, 2017. The success of CAA hinges on the behavior of three act… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

1
14
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
4
2
2

Relationship

1
7

Authors

Journals

citations
Cited by 31 publications
(15 citation statements)
references
References 23 publications
1
14
0
Order By: Relevance
“…There are also results on the submetric level of other SMGs which are worth discussing. The CAA Submetric's results, for example, confirm an observation already reported by Scheitle et al [60]. Although consistently rejecting CSRs with a conflicting issue property tag in the CAA RR, none of the assessed CAs makes use of iodef notifications in the case of rejection.…”
Section: Hypothesessupporting
confidence: 85%
“…There are also results on the submetric level of other SMGs which are worth discussing. The CAA Submetric's results, for example, confirm an observation already reported by Scheitle et al [60]. Although consistently rejecting CSRs with a conflicting issue property tag in the CAA RR, none of the assessed CAs makes use of iodef notifications in the case of rejection.…”
Section: Hypothesessupporting
confidence: 85%
“…Scheitle et al [35] surveyed the adoption of the CAA record and compliance to it. Compared to our work they examine the CAA mechanism only, but in greater depth as they uncover certificate misissuance with deliberately broken CAA configurations.…”
Section: Related Workmentioning
confidence: 99%
“…CAA Adoption: Exemplary for other record types, we also investigate the adoption of Certification Authority Authorization (CAA) records in top lists and the general population. CAA is a rather new record type, and has become mandatory for CAs to check before certificate issuance, cf., [122,128]. We measure CAA adoption as described in [122], i.e., the count of base domains with an issue or issuewild set.…”
Section: Alexamentioning
confidence: 99%
“…CAA is a rather new record type, and has become mandatory for CAs to check before certificate issuance, cf., [122,128]. We measure CAA adoption as described in [122], i.e., the count of base domains with an issue or issuewild set. Similar to IPv6 adoption, we find CAA adoption among top lists (1-2%) to significantly exceed adoption among the general population at 0.1%.…”
Section: Alexamentioning
confidence: 99%