SSL is the primary technology used to secure web communications. Before setting up an SSL connection, web browsers have to validate the SSL certificate of the web server in order to ensure that users access the expected web site. We have tested the handling of the main fields in SSL certificates and found that web browsers do not process them in a homogenous way. An SSL certificate can be accepted by some web browsers whereas a message reporting an error can be delivered to users by other web browsers for the same certificate. This diversity of behavior might cause users to believe that SSL certificates are unreliable or error prone, which might lead them to consider that SSL certificates are useless. In this paper, we highlight these different behaviors and we explain the reasons for them which can be either a violation of the standards or ambiguity in the standards themselves. We give our opinion of which it is in our analysis. © IFIP International Federation for Information Processing 2009.
CITATION STYLE
Wazan, A. S., Laborde, R., Chadwick, D. W., Barrere, F., & Benzekri, A. M. (2009). Which web browsers process SSL certificates in a standardized way? In IFIP Advances in Information and Communication Technology (Vol. 297, pp. 432–442). https://doi.org/10.1007/978-3-642-01244-0_38
Mendeley helps you to discover research relevant for your work.