Skip to main content

Published on 1 May 2012

Publication technical report - Attacks against certification service providers and their ramifications

01.05.2012 - The Reporting and Analysis Centre for Information Assurance MELANI publishes technical reports in the area of Information Assurance at irregular intervals. The reports will deepen actual topics related to incidents and ocurrences in the information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context. The second publication brings up the attacks against certification service providers.

In the recent past, various established certification service providers (CSPs) regarded as trustworthy by browser manufacturers have been attacked and in at least two cases (Comodo and DigiNotar) also compromised. The attackers succeeded in issuing bogus SSL/TLS server certificates with which large-scale man-in-the-middle (MITM) attacks were carried out. As part of this technological consideration, we will show what happened and the ramifications the attacks may have on the design of current and future public key infrastructures (PKIs).

Attacks against certification service providers and their ramifications