Re-Check Your Certificates! Experiences and Lessons Learnt from Real-World HTTPS Certificate Deployments

Wenya Wang,Yakang Li,Chao Wang,Yuan Yan,Juanru Li,Dawu Gu
DOI: https://doi.org/10.1007/978-3-030-92708-0_2
2021-01-01
Abstract:HTTPS is the typical security best practice to protect data transmission. However, it is difficult to correctly deploy HTTPS even for administrators with technical expertise, and mis-configurations often lead to user-facing errors and potential vulnerabilities. One major reason is that administrators do not follow new features of HTTPS ecosystem evolution, and mistakes were unnoticed and existed for years.
What problem does this paper attempt to address?