Old Habits Die Hard: A Sober Look at TLS Client Certificates in the Real World

Wei Xia, Wei Wang, Xin He, Gang Xiong, Gaopeng Gou, Zhenzhen Li, Zhen Li · 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) · 2021

Certificates play a key role in TLS, which is by far the most widely used security protocol for protecting network traffic. Studies have shown that inappropriate usage of certificates may incur security and privacy risks, most of which are focused on the server-side certificates. However, with the rapid development of the Internet of Things that interconnects countless nodes over the world, as well as the Zero Trust philosophy that stresses authentication of every entity, the adoption of client certificates could be a lot more vital. According to our observation, many practical problems and security risks still exist in the deployment and use of client certificates. In this paper, we present a passive measurement of over 24 million client certificates, collected by a framework deployed on the CSTNET, one of the major academic backbone networks in China. By performing a comprehensive analysis of the large scale real-world data, we give a big picture of the client certificates usage in current network, and disclose implementation flaws of these certificates which may possibly harm transport layer security and user privacy. As many as 342,699 defective client certificates are unearthed, which is an important reminder that never should we neglect the correct use of certificates on the client side.

Read the paper · More papers on PaperTik