Exploring HTTPS Certificate Ecosystem: Analyzing the Entire IPv4 Address Space
Sina Keshvadi, Yogesh Sharma · 2023
HTTPS, a widely adopted protocol for secure communication on the internet, relies on the TLS protocol to ensure encryption and authentication during data transmission. In this study, we conducted a large-scale measurement on the entire IPv4 address space to analyze the TLS certificate ecosystem used in HTTPS. Over eight consecutive days, we found 46.80M hosts with an open 443 port, of which 33.36M (71.2%) successfully completed a TLS handshake, and we collected 27.88M unique SSL/TLS certificates. This paper presents an overview of the certificate status and distribution, including the prevalence of untrusted and expired certificates. We found that TLS 1.2 is still widely used, accounting for 53.80% of all TLS protocol usage, while TLS 1.3 has shown a significant increase in usage, reaching 43.20% of all TLS protocol usage. Our study also investigates the certificate authorities that issued the certificates, revealing a diverse set of organizations, with Let’s Encrypt being the most prominent one. We compare our results with a study conducted a decade ago to examine the changes in the TLS certificate ecosystem. The findings propose implications for internet security and highlight the need for improved certificate management and monitoring practices.