Bakalářská práce
Získaná ocenění: Cena děkana FI za vynikající závěrečnou práci

Comparing X.509 certificate validation errors across TLS libraries

Pavol Žáčik
Anotace

Počas práce s protokolom TLS sa vývojári často stretávajú s chybami pri validácii certifikátov. V takých situáciách môžu byť ich rozhodnutia kritické vzhľadom na bezpečnosť implementovaných systémov. Chybové hlášky sa však medzi TLS knižnicami líšia, pričom ich oficiálna dokumetácia vo väčšine prípadov nie je veľmi nápomocná. Táto práca porovnáva chyby validácie certifikátov v piatich často používaných …více

Abstract

IT professionals often meet certificate validation errors when dealing with TLS. In such situations, their decisions may be crucial for the security of systems they implement. However, error messages differ depending on the used TLS library, and official documentation usually does not help much. This thesis performs a comparison of certificate validation errors occurring in five common TLS libraries …více

Zadání práce

Transport Layer Security (TLS) is a rather complex protocol suite for securing data transfer on the Internet. A lot of its security stems from correctly validating certificates of the communicating parties. However, different TLS libraries have very different certificate validation errors and transferring knowledge from one to another is difficult. In the project "Usable certificate validation" (x509errors.org), we aim to improve the situation.

This thesis aims to compare X.509 certificate validation errors across multiple common TLS-enabled libraries. Specifically, the student will:

  • Create well-documented implementation of establishing TLS connections with properly checking the certificate validity for at least three common TLS-enabled libraries. These implementations should be published, aiming to be used as referential by other programmers.
  • Generate malformed certificate chains that demonstrate as many certificate validation errors as possible (at least fifty). The generation should be performed in a reliable and reproducible manner.
  • Based on the code and certificates from the previous two points, create a correspondence mapping among X.509 errors across TLS libraries. Briefly evaluate the obtained data.

The thesis is a part of usable security research activities in CRoCS. The specific thesis assignment is up to discussion with the student taking into account his/her experience and interests. The prerequisites include basic knowledge of security and willingness to flexibly learn new knowledge and skills. Previous experience with quantitative data analysis is an advantage but can be learned in the process.

Práce zkontrolována:
26. 5. 2021 09:04, RNDr. Martin Ukrop, Ph.D., učo 374297
Jazyk práce
angličtina angličtina
Termín obhajoby
30. 6. 2021
Práce byla úspěšně obhájena

Vedoucí

RNDr. Martin Ukrop, Ph.D., učo 374297
KTP FI MU

Oponent

RNDr. Agáta Kružíková, Ph.D.
KPSK FI MU

Masarykova univerzita Fakulta informatiky
Studijní program
Informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.