Understanding Student Experiences with TLS Client Authentication

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shittu, Abubakar Sadiq, Shubert, Clay, Sadik, John, Ruoti, Scott
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918476186124288
author Shittu, Abubakar Sadiq
Shubert, Clay
Sadik, John
Ruoti, Scott
author_facet Shittu, Abubakar Sadiq
Shubert, Clay
Sadik, John
Ruoti, Scott
contents Mutual TLS (mTLS) provides strong, certificate-based authentication for both clients and servers, yet its adoption for user-facing websites remains rare. This paper presents a longitudinal study of mTLS usability, tracking 46 senior and graduate computer science students who configured client certificates from scratch, used them for routine authentication over a semester-long course, and managed credentials across multiple devices. The results reveal that initial setup is a major bottleneck; while daily use was considered smooth, it did not improve long-term usability perceptions. Most concerningly, only 9% of participants fully understood the security implications of certificate-based authentication. We conclude that in a realistic, tooling-heavy deployment utilizing OpenSSL, a custom CA, and a 3072-bit minimum key requirement, even highly technical students struggled significantly. We argue this provides empirical evidence that today mTLS user experience is fundamentally misaligned with non-PKI specialists, and it is difficult to see a path toward mainstream adoption without substantial platform-level changes.
format Preprint
id arxiv_https___arxiv_org_abs_2604_14330
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Understanding Student Experiences with TLS Client Authentication
Shittu, Abubakar Sadiq
Shubert, Clay
Sadik, John
Ruoti, Scott
Cryptography and Security
Mutual TLS (mTLS) provides strong, certificate-based authentication for both clients and servers, yet its adoption for user-facing websites remains rare. This paper presents a longitudinal study of mTLS usability, tracking 46 senior and graduate computer science students who configured client certificates from scratch, used them for routine authentication over a semester-long course, and managed credentials across multiple devices. The results reveal that initial setup is a major bottleneck; while daily use was considered smooth, it did not improve long-term usability perceptions. Most concerningly, only 9% of participants fully understood the security implications of certificate-based authentication. We conclude that in a realistic, tooling-heavy deployment utilizing OpenSSL, a custom CA, and a 3072-bit minimum key requirement, even highly technical students struggled significantly. We argue this provides empirical evidence that today mTLS user experience is fundamentally misaligned with non-PKI specialists, and it is difficult to see a path toward mainstream adoption without substantial platform-level changes.
title Understanding Student Experiences with TLS Client Authentication
topic Cryptography and Security
url https://arxiv.org/abs/2604.14330