Certificate Root Stores: An Area of Unity or Disparity?

Jegan Purushothaman,Ethan Thompson,AbdelRahman Abdou
DOI: https://doi.org/10.48550/arXiv.2110.11488
2021-10-21
Cryptography and Security
Abstract:Organizations like Apple, Microsoft, Mozilla and Google maintain certificate root stores, which are used as trust anchors by their software platforms. Is there sufficient consensus on their root-store inclusion and trust policies? Disparities appear astounding, including in the government-owned certificates that they trust. Such a status-quo is alarming.
What problem does this paper attempt to address?