Závěrečná práce: Pavol Žáčik: Comparing X.509 certificate validation errors across TLS libraries
Bakalářská práce
Comparing X.509 certificate validation errors across TLS libraries
Anotace
Počas práce s protokolom TLS sa vývojári často stretávajú s chybami pri validácii certifikátov. V takých situáciách môžu byť ich rozhodnutia kritické vzhľadom na bezpečnosť implementovaných systémov. Chybové hlášky sa však medzi TLS knižnicami líšia, pričom ich oficiálna dokumetácia vo väčšine prípadov nie je veľmi nápomocná. Táto práca porovnáva chyby validácie certifikátov v piatich často používaných …více
Abstract
IT professionals often meet certificate validation errors when dealing with TLS. In such situations, their decisions may be crucial for the security of systems they implement. However, error messages differ depending on the used TLS library, and official documentation usually does not help much. This thesis performs a comparison of certificate validation errors occurring in five common TLS libraries …více
Zadání práce
Transport Layer Security (TLS) is a rather complex protocol suite for securing data transfer on the Internet. A lot of its security stems from correctly validating certificates of the communicating parties. However, different TLS libraries have very different certificate validation errors and transferring knowledge from one to another is difficult. In the project "Usable certificate validation" (x509errors.org), we aim to improve the situation.
This thesis aims to compare X.509 certificate validation errors across multiple common TLS-enabled libraries. Specifically, the student will:
- Create well-documented implementation of establishing TLS connections with properly checking the certificate validity for at least three common TLS-enabled libraries. These implementations should be published, aiming to be used as referential by other programmers.
- Generate malformed certificate chains that demonstrate as many certificate validation errors as possible (at least fifty). The generation should be performed in a reliable and reproducible manner.
- Based on the code and certificates from the previous two points, create a correspondence mapping among X.509 errors across TLS libraries. Briefly evaluate the obtained data.
The thesis is a part of usable security research activities in CRoCS. The specific thesis assignment is up to discussion with the student taking into account his/her experience and interests. The prerequisites include basic knowledge of security and willingness to flexibly learn new knowledge and skills. Previous experience with quantitative data analysis is an advantage but can be learned in the process.
26. 5. 2021 09:04, RNDr. Martin Ukrop, Ph.D., učo 374297
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Usability of cryptographic interfaces
RNDr. Martin Ukrop, Ph.D., učo 374297 -
Investigating certificate revocation options
Ing. Marián Svitek -
Usability analysis of TLS API documentation
Mgr. Matěj Kolouch Grabovský -
Two Cases of Human-Centered Computer Science: Usable Developer Interaction with TLS Certificates and Effective Teaching Assistant Training
RNDr. Martin Ukrop, Ph.D., učo 374297 -
Security building blocks of cryptocurrencies hardware wallets
Mgr. Adam Parák, učo 485720 -
Řízení úseku odborného výcviku
Bc. Marie Mácová -
Spomienky pamätníkov ako zbierkový predmet múzeí
Mgr. Anna Andrisová -
Ohledání místa činu jako neodkladný a neopakovatelný úkon
Mgr. Alena Opelková




