<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-20T15:45:36Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/100897" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/100897</identifier>
        <datestamp>2023-07-11</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_8888</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_8887</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:title>Tracking certificate misissuance in the wild</dc:title>
          <dc:type>text</dc:type>
          <dc:type>text</dc:type>
          <dc:contributor>Bailey, Michael D</dc:contributor>
          <dc:creator>Wang, Zhengping</dc:creator>
          <dc:date>2018-09-04T20:26:32Z</dc:date>
          <dc:date>2018-09-04T20:26:32Z</dc:date>
          <dc:date>2018-02-01</dc:date>
          <dc:date>2018-05</dc:date>
          <dc:description>Certificate Authorities (CAs) are responsible for delegating trust in the TLS Public Key Infrastructure (PKI). Unfortunately, there is a long history of CAs abusing this responsibility, either due to negligence or in some cases, falling victim to attacks. As a result, the PKI community has established standards that define the correctness of certificates and how a well managed CA should operate. In this work, we evaluate a systematic approach to identifying whether certificates issued by CAs are compliant with community standards. To this end, we present ZLint, a system that determines whether a certificate is not conformant to standards, i.e., misissued. We find that while misissuance has decreased over time, there is still a long tail of non-conformant CAs in the ecosystem. Further, our results show that certificate misissuance serves as a reasonable indicator for mismanagement and untrustworthiness, suggesting that CAs that misissue more frequently pose a greater threat to security of the PKI. Community efforts thus far to curb these threats have been moderately successful, but the lack of a systematic approach to identifying these problems lets some classes of problems slip through the cracks. We argue that an automated and systematic approach to measuring misissuance in the ecosystem is a necessary first step in solving the problems that lie ahead.</dc:description>
          <dc:description>Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2018-08-31 without embargo terms</dc:description>
          <dc:description>The student, Zhengping Wang, accepted the attached license on 2018-02-01 at 09:41.</dc:description>
          <dc:description>The student, Zhengping Wang, submitted this Thesis for approval on 2018-02-01 at 09:53.</dc:description>
          <dc:description>This Thesis was approved for publication on 2018-02-01 at 14:04.</dc:description>
          <dc:description>DSpace SAF Submission Ingestion Package generated from Vireo submission #12030 on 2018-08-31 at 17:08:15</dc:description>
          <dc:description>Made available in DSpace on 2018-09-04T20:26:32Z (GMT). No. of bitstreams: 2
WANG-THESIS-2018.pdf: 440123 bytes, checksum: 7cb1b3735d3ed38c245c0442a5bedd10 (MD5)
LICENSE.txt: 4211 bytes, checksum: c5c7db273405fbecd4c6d8dbf9295bc1 (MD5)
  Previous issue date: 2018-02-01</dc:description>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>http://hdl.handle.net/2142/100897</dc:identifier>
          <dc:language>en</dc:language>
          <dc:rights>Copyright 2018 Zhengping Wang</dc:rights>
          <dc:subject>Certificate</dc:subject>
          <dc:subject>Misissuance</dc:subject>
          <degree>
            <department>Electrical &amp; Computer Eng</department>
            <discipline>Electrical &amp; Computer Engr</discipline>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <level>Thesis</level>
            <name>M.S.</name>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
