Security Analysis of Middleware Based on SSL Certificate Authentication
Xiao Hui He · Journal of Sichuan University of Science & Engineering · 2014
Secure Socket Layer(SSL) certificate authentication has the trust chain,host authentication,certificate revocation and extension mechanism. The use of SSL library in the abstract SSL protocol stack is defined,and the setting method of default value used to connection is expanded. Then,it expounds that the trust chain validation OpenSSL application interfaces have different valid hostname composition limit and matching requirements of certificate list. Based on the analysis of HTTPS connection mechanism built by OpenSSL internal data structure and data transport layer,the defect that JSSE does not perform its host authentication to build SSL connection is revealed,and then the solving strategy that realize automatic check whether the application is correct to use key options and parameters of SSL library by formal verification techniques and programming,is put forward.