HOW TO STRENGTHEN CERTIFICATE ENROLLMENT
Tobias Straub · 2004
Many PKIs implement certificate enrollment using a registration and a certifi- cation authority. However, the standard protocol has a weakness since the intended sequence of steps in the process cannot be enforced rigorously. In the current paper, we present a new enrollment protocol to remedy this flaw. Our method provides security by means of shared signatures and distributed key generation while at the same time producing standard- compliant certificates signed with RSA or DSA. Introduction Certificate enrollment denotes the process of initializing a new user in a public key in- frastructure (PKI) which is a routine yet security-critical task. To underline a weakness in the standard protocol, we sketch a typical realization below. In this paper, we focus on hierarchical PKIs and assume that certificates are issued by a central and trustworthy party, the certification authority (CA). To enroll in the PKI, a user generates a key pair e.g. by means of his web browser and sends the corresponding certification request (e.g. a PKCS#10 file) to the registration authority(RA). This message needs to be authenticated, e.g. by the user presenting himself at the RA, to establish a binding between the entity and the public key. The RA collects and verifies requests which are then transferred to the CA in a digitally signed container like a PCKS#7 file. Finally, the CA issues the corresponding certificates and publishes them in an online directory. Security reasons motivate the RA/CA distinction: Firstly, to protect the PKI's certification key, the CA uses it only in a safe environment, typically on a computer disconnected from the network. The second reason is that a certificate can only be as strong (i.e. meaningful) as the underlying registration process. Thus, PKIs often decentralize this task using a number of RAs to be closer to the end-user. The implicit idea behind sharing responsibilities is to achieve a four-eye or double verification principle. Instead of enforcing this rule with cryptography, PKIs nowadays rely on organizational and procedural controls and - in the end - on a supposed RA/CA trust relationship. This exposes the PKI to danger since it does not effectively prevent the CA from deviating from the protocol. For instance, a fraudulent employee having access to the certification key is able to issue certificates even if there are no corresponding requests signed by an RA. 1 This weakness is intolerable, especially when RA and CA are operated by two different