[TLS] Eleven out of every ten SSL certs aren't valid

Peter Gutmann <pgut001@cs.auckland.ac.nz> Tue, 29 June 2010 07:50 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id ED8283A67F7 for <tls@core3.amsl.com>; Tue, 29 Jun 2010 00:50:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.762
X-Spam-Level:
X-Spam-Status: No, score=-0.762 tagged_above=-999 required=5 tests=[AWL=-0.763, BAYES_50=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NEc7ozsziNG3 for <tls@core3.amsl.com>; Tue, 29 Jun 2010 00:50:31 -0700 (PDT)
Received: from mx2-int.auckland.ac.nz (mx2-int.auckland.ac.nz [130.216.12.41]) by core3.amsl.com (Postfix) with ESMTP id 32D633A698B for <tls@ietf.org>; Tue, 29 Jun 2010 00:50:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=pgut001@cs.auckland.ac.nz; q=dns/txt; s=uoa; t=1277797842; x=1309333842; h=from:to:subject:message-id:date; z=From:=20Peter=20Gutmann=20<pgut001@cs.auckland.ac.nz> |To:=20tls@ietf.org|Subject:=20Eleven=20out=20of=20every =20ten=20SSL=20certs=20aren't=20valid|Message-Id:=20<E1OT VaY-0004g3-OW@wintermute02.cs.auckland.ac.nz>|Date:=20Tue ,=2029=20Jun=202010=2019:50:38=20+1200; bh=OFTOgUBxx7BwncOzsFM4BFiu+MB34oL/DeAUlubuoqY=; b=fNrIfnswoQMZQmWde730ZRzeKsRFUROy2YQNU5OSKiPwXX5Yn7aR8Clp +o2RPXfAQmeQbBX1NeKZYKJ8LWzNBV1DOHND/kRZf8dV37ZxGj8LiscS+ nRIewUnTfFbUN/bPqbRDLBreAxGhAeNPz8o+n7kWMR4hP3I+NlIL7X/OK g=;
X-IronPort-AV: E=Sophos;i="4.53,503,1272801600"; d="scan'208";a="13143089"
X-Ironport-HAT: UNIVERSITY - $RELAY-THROTTLE
X-Ironport-Source: 130.216.207.92 - Outgoing - Outgoing
Received: from wintermute02.cs.auckland.ac.nz ([130.216.207.92]) by mx2-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 29 Jun 2010 19:50:39 +1200
Received: from pgut001 by wintermute02.cs.auckland.ac.nz with local (Exim 4.69) (envelope-from <pgut001@cs.auckland.ac.nz>) id 1OTVaY-0004g3-OW for tls@ietf.org; Tue, 29 Jun 2010 19:50:38 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: tls@ietf.org
Message-Id: <E1OTVaY-0004g3-OW@wintermute02.cs.auckland.ac.nz>
Date: Tue, 29 Jun 2010 19:50:38 +1200
Subject: [TLS] Eleven out of every ten SSL certs aren't valid
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jun 2010 07:50:37 -0000

In case someone here still hasn't seen this, the subject is a reference to:

  SSL Certificates In Use Today Aren't All Valid
  http://www.esecurityplanet.com/features/article.php/3890171/SSL-Certificates-In-Use-Today-Arent-All-Valid.htm

which posits that only 3% of SSL certs in use today are valid.  The figures
seem a bit suspicious though, for example they claim 23 million SSL sites
while the same article quotes Netcraft as claiming there are 1.5 million SSL
certs in use (the Netcraft figures may be for CA-issued certs only, since they
quote Verisign as a percentage of that total).  Still, 3% seems pretty low,
could this be due to something like virtual hosting and the client not sending
the hostname, thereby getting the wrong cert?  Even with that though, I 
wouldn't have expected a 97% invalidity rate.

Peter.