Robert Everett Schwartz
Adversarial certificate-based testing of mTLS (mutual TLS) handshakes for test-driven development.
Rel. Fulvio Corno, Luca Ardito. Politecnico di Torino, Master of science program in Computer Engineering, 2024
Abstract
TLS handshake implementations are often difficult to comprehensively test. This is in part due to the complexity of the X.509 certificate specification and its influence on relationships between certificates (for example, tests should check for “cA” in Basic Constraints before verifying relevant certificate authority signatures, and should also test that all certificates are currently valid). Even when the TLS protocol seems to be implemented correctly, subtle vulnerabilities in certificate validation can still occur and may only appear in edge cases. Contributing factors include incomplete implementation of the X.509 specification, relative weakness of cybersecurity as a part of the software development lifecycle, and the traditional software development perspective that certificate generation is an uncommon procedure (in contrast to DevOps, microservices, or certificate-rotation based strategies).
mTLS (mutual TLS) is used by applications to create a zero-trust architecture: the mTLS protocol proposes that both the server and client (or two nodes more generally) are untrusted and that each must authenticate the other
Relators
Academic year
Publication type
Number of Pages
Additional Information
Course of studies
Classe di laurea
Aziende collaboratrici
URI
![]() |
Modify record (reserved for operators) |
