Baseline Requirements for the issuance and management of publicly-trusted certificates, v1.7.2 (2020). https://cabforum.org/baseline-requirements-documents/
OneCRL (CA/Revocation Checking in Firefox) (2020) https://wiki.mozilla.org/CA:RevocationPlan#OneCRL
Apple: About upcoming limits on trusted certificates (2020). https://support.apple.com/en-us/HT211025
Chuat, L., Abdou, A., Sasse, R., Sprenger, C., Basin, D., Perrig, A.: SoK: delegation and revocation, the missing links in the Web’s chain of trust. In: Proceedings of IEEE EuroS&P (2020)
Google Scholar
Chung, T., et al.: Is the Web ready for OCSP must-staple? In: Proceedings of IMC (2018)
Google Scholar
Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., Polk, W.: Internet X.509 Public Key Infrastructure certificate and Certificate Revocation List (CRL) profile. RFC 5280, May 2008
Google Scholar
Deacon, A., Hurst, R.: The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume Environments. RFC Editor, RFC 5019, September 2007
Google Scholar
DigiCert: DigiCert: Delay of revocation for EV audit inconsistency incident (2020). https://bugzilla.mozilla.org/show_bug.cgi?id=1651828
DigiCert: Inconsistent EV audits (2020). https://bugzilla.mozilla.org/show_bug.cgi?id=1650910
Durumeric, Z., Adrian, D., Mirian, A., Bailey, M., Halderman, J.A.: A search engine backed by Internet-wide scanning. In: Proceedings of ACM CCS (2015)
Google Scholar
Google: CRLSets. https://dev.chromium.org/Home/chromium-security/crlsets. Accessed Sept 2020
Google: Certificate lifetimes (2020). https://chromium.googlesource.com/chromium/src/+/master/net/docs/certificate_lifetimes.md
Google Trust Services: Certificate Policy v1.3. https://pki.goog/GTS-CP-1.3.pdf, OID = 1.3.6.1.4.1.11129.2.5.3. Accessed 21 Jan 2021
Gustafsson, J., Overier, G., Arlitt, M., Carlsson, N.: A first look at the CT landscape: Certificate Transparency logs in practice. In: Proceedings of PAM, March 2017
Google Scholar
Internet Security Research Group (ISRG): Certification Practice Statement, Version 3.0, October 2020. http://cps.letsencrypt.org. Accessed 21 Jan 2021
Kim, D., Kwon, B.J., Kozák, K., Gates, C., Dumitras, T.: The broken shield: measuring revocation effectiveness in the Windows code-signing PKI. In: Proceedings of USENIX Security, August 2018
Google Scholar
Koblitz, N.: Elliptic curve cryptosystems. Math. Comput. 48(177), 203–209 (1987)
Article
MathSciNet
Google Scholar
Korzhitskii, N., Carlsson, N.: Characterizing the root landscape of Certificate Transparency logs. In: Proceedings of IFIP Networking, June 2020
Google Scholar
Korzhitskii, N., Carlsson, N.: Dataset for “Revocation Statuses on the Internet” PAM 2021 paper (2021). https://www.ida.liu.se/~nikca89/papers/pam21.html
Laurie, B., Langley, A., Kasper, E.: Certificate Transparency. RFC 6962 (2013)
Google Scholar
Let’s Encrypt: 2020.02.29 CAA Rechecking Bug, March 2020. https://community.letsencrypt.org/t/2020-02-29-caa-rechecking-bug/114591/3
Let’s Encrypt: Download affected certificate serials for 2020.02.29 CAA Rechecking Incident, March 2020. https://letsencrypt.org/caaproblem/
Liu, Y., et al.: An end-to-end measurement of certificate revocation in the Web’s PKI. In: Proceedings of IMC (2015)
Google Scholar
Mozilla (2020). https://blog.mozilla.org/security/2020/07/09/reducing-tls-certificate-lifespans-to-398-days/
O’Brien, D.: Certificate Transparency Enforcement in Chrome and CT Day in London (2018). https://groups.google.com/a/chromium.org/d/msg/ct-policy/Qqr59r6yn1A/2t0bWblZBgAJ. Accessed Jan 2021
Rivest, R.L., Shamir, A., Adleman, L.: A method for obtaining digital signatures and public-key cryptosystems. Commun. ACM 21(2), 120–126 (1978)
Article
MathSciNet
Google Scholar
SANS Internet Storm Center: SSL CRL activity. https://isc.sans.edu/crls.html. Accessed Sept 2020
Santesson, S., Myers, M., Ankney, R., Malpani, A., Galperin, S., Adams, C.: X.509 Internet public key infrastructure online certificate status protocol - OCSP. RFC Editor, RFC 6960, June 2013
Google Scholar
Santesson, S., Myers, M., Ankney, R., Malpani, A., Galperin, S., Adams, C.: X. 509 internet public key infrastructure online certificate status protocol-ocsp. RFC 6960 (2013)
Google Scholar
Scheitle, Q., et al.: The rise of Certificate Transparency and its implications on the Internet ecosystem. In: Proceedings of IMC (2018)
Google Scholar
Sectigo: Certificate search. https://crt.sh. Accessed Sept 2020
Smith, T., Dickinson, L., Seamons, K.: Let’s revoke: scalable global certificate revocation. In: Proceedings of NDSS (2020)
Google Scholar
Starfield Technologies, LLC: Certificate Policy and Certification Practice Statement (CP/CPS), Version 4.9, October 2020. http://certificates.godaddy.com/repository/. Accessed 21 Jan 2021
Zhu, L., Amann, J., Heidemann, J.: Measuring the latency and pervasiveness of TLS certificate revocation. In: Proceedings of PAM (2016)
Google Scholar