SSCP Systems Security Certified PractitionerCryptographyMedium
A security auditor is reviewing a client's Certificate Revocation List (CRL) distribution points. The auditor observes that the CRLs are being distributed over HTTP without any additional security measures. What is the primary security concern with this distribution method?
- APerformance bottleneck due to large CRL sizes
- BVulnerability to denial-of-service attacks
- CDifficulty in certificate validation for clients
- DLack of integrity and authenticity for the CRL
Show answer & explanationAnswer & explanation
Correct answer: D. Lack of integrity and authenticity for the CRL
Distributing CRLs over plain HTTP means that an attacker could tamper with the CRL (e.g., remove a revoked certificate) or substitute it with an old or forged one. Without integrity checks (like a digital signature on the CRL itself) and authenticity, clients might accept revoked certificates as valid, undermining the PKI's security. CRLs are typically signed by the CA to address this.
Why the other options are wrong
- A. Large CRL sizes are a concern for performance, but not the primary security vulnerability related to HTTP distribution.
- B. DoS attacks are a general concern for any public service, but not the most direct cryptographic concern for unsecured HTTP CRL distribution.
- C. While it might make validation challenging due to trust issues, the direct cryptographic concern is the lack of protection for the CRL data itself.
CRL Integrity and Authenticity
Ensuring that a Certificate Revocation List (CRL) has not been tampered with and genuinely originates from the issuing Certificate Authority (CA) to prevent clients from accepting revoked certificates.
- CRLs are digitally signed by the CA.
- Signature verification confirms integrity and authenticity.
- Unsecured distribution (e.g., plain HTTP) allows tampering.
Memory trick: CRL's Sign Proves Its Truth.