Posts

Showing posts from April, 2022

statcert: a new tool to identify the type of X.509 certificates and their revocation status

Image
Today three types of certificates are used by the web: DV, OV, and EV. The DV certificates only ensure that the certificate owner has the right to control the domain name. Still, it doesn't provide any information about the owner's identity. On the other hand, the OV certificate lets one know that the owner has the right to use the domain name, but it gives more information about the domain name's owner, such as the organization name and the country. Finally, the EV certificates are similar to OV, but they provide more information about the owner, and the verification procedures of the owner information are more strict. Web users have to trust a website that uses an EV certificate more than a website that uses a DV or OV certificate. However, it is difficult for a web user to distinguish these certificates as the web browsers have decided to remove all the visual indicators for EV certificates. We have built a new tool called statcert that allows us to know the type of X.50...