Certificate Authorities (CAs) are a cornerstone of web security, as browsers and applications fully trust authentication assertions issued by them. Root stores in user devices contain the CAs that serve as trust anchors for certificate validation. However, these root CAs often extend their authority to organizations outside their administrative boundaries, known as intermediate CAs. Although root stores have been extensively studied in previous work, intermediate CAs have received little attention, despite their equivalent authentication capabilities and crucial role in determining the actual perimeter of trust. This work provides the first systematic overview of the intermediate CA ecosystem in the Web Public Key Infrastructure (Web PKI). Starting from the Mozilla root store, we investigate over 1800 CA certificates and find that trust extends well beyond the root store: 150 additional CAs from 18 countries not represented among root CAs are implicitly trusted by any relying party. We show that root CAs delegate trust to intermediate CAs in countries with substantial political distance from their own, substantially expanding the geopolitical diversity of trusted certificate issuers. Finally, by cross-referencing our dataset against Certificate Transparency Logs, we identify CAs that violate Mozilla's mandatory disclosure policies, further undermining the ecosystem's transparency.

Beyond the Roots: Exploring the Intermediate CA Ecosystem in the Web PKI / Farina, M., Trevisan, M., Bartoli, A.. - (2026), pp. ---. (The International Conference on Availability, Reliability and Security - ARES Linköping, Sweden August 2026).

Beyond the Roots: Exploring the Intermediate CA Ecosystem in the Web PKI

Farina Mauro
;
Trevisan Martino;Bartoli Alberto
2026-01-01

Abstract

Certificate Authorities (CAs) are a cornerstone of web security, as browsers and applications fully trust authentication assertions issued by them. Root stores in user devices contain the CAs that serve as trust anchors for certificate validation. However, these root CAs often extend their authority to organizations outside their administrative boundaries, known as intermediate CAs. Although root stores have been extensively studied in previous work, intermediate CAs have received little attention, despite their equivalent authentication capabilities and crucial role in determining the actual perimeter of trust. This work provides the first systematic overview of the intermediate CA ecosystem in the Web Public Key Infrastructure (Web PKI). Starting from the Mozilla root store, we investigate over 1800 CA certificates and find that trust extends well beyond the root store: 150 additional CAs from 18 countries not represented among root CAs are implicitly trusted by any relying party. We show that root CAs delegate trust to intermediate CAs in countries with substantial political distance from their own, substantially expanding the geopolitical diversity of trusted certificate issuers. Finally, by cross-referencing our dataset against Certificate Transparency Logs, we identify CAs that violate Mozilla's mandatory disclosure policies, further undermining the ecosystem's transparency.
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11368/3143518
 Avviso

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact