Flexible Electronics News

Leading European Trust Service Providers Pilot Independent Solution for More SSL Certificates Security

Developing a pan-European security system for SSL certificates

Author Image

By: DAVID SAVASTANO

Contributing Editor, Coatings World and Ink World

Three leading European Trust Service Providers – German D-TRUST GmbH, SwissSign AG from Switzerland and Spanish Izenpe S.A. – have launched an initiative to develop a pan-European security system for SSL certificates. This is in response to the “Certificate Transparency” effort announced by Google, which is designed to identify mis-issuance of certificates from Trust Service Providers and to ban them from secure Internet communications.

In July last year, all certification authorities represented in the “Certification Authority Browser Forum” (CA/Browser Forum) already adopted the “baseline requirements” as certain fundamental security requirements. One of these requirements is that, as of next spring, the web browsers which are in use world-wide will only accept certificates with a minimum key length of 2,048 bits and a maximum term of validity of five years.

In order to be able to monitor and audit these requirements, Google developed the “Certificate Transparency” framework. Its underlying idea is that all certificates used for secure Internet communications have to be registered and managed by log servers in a cryptographically protected log system. Any subsequent modifications of, additions to, or other manipulations of a certificate, once registered, would thus be ruled out or would be immediately detected by every browser.

“This concept, which is especially driven by Google Chrome, will become an important cornerstone of trusted Internet communications,” said Dr. Kim Nguyen, CEO of German D-TRUST GmbH, a subsidiary of Bundesdruckerei GmbH. “However, the necessary registration systems – so-called ‘certificate logs’ – are so far only available from U.S. providers, and in view of this heavily reputation-based trust model, we consider it to be extremely important that European interests are also taken into consideration.”

Against this background, the stakeholders D-TRUST, SwissSign and Izenpe decided to launch a pilot for a separate certificate log which is to support the Certificate Transparency model via a fully independent log infrastructure. It also makes it possible to coordinate this with global web browser providers, such as Google, Apple, Microsoft or Mozilla.

Keep Up With Our Content. Subscribe To Ink World magazine Newsletters