A Call to Reconsider Certification Authority Authorization (CAA)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tehrani, Pouyan Fotouhi, Hiesgen, Raphael, Schmidt, Thomas C., Wählisch, Matthias
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912878004535296
author Tehrani, Pouyan Fotouhi
Hiesgen, Raphael
Schmidt, Thomas C.
Wählisch, Matthias
author_facet Tehrani, Pouyan Fotouhi
Hiesgen, Raphael
Schmidt, Thomas C.
Wählisch, Matthias
contents Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine its effectiveness in preventing certificate misissuance. Our discussion reveals pitfalls and highlights best practices when designing security protocols based on DNS.
format Preprint
id arxiv_https___arxiv_org_abs_2411_07702
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Call to Reconsider Certification Authority Authorization (CAA)
Tehrani, Pouyan Fotouhi
Hiesgen, Raphael
Schmidt, Thomas C.
Wählisch, Matthias
Cryptography and Security
Networking and Internet Architecture
Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine its effectiveness in preventing certificate misissuance. Our discussion reveals pitfalls and highlights best practices when designing security protocols based on DNS.
title A Call to Reconsider Certification Authority Authorization (CAA)
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2411.07702