Collected research
mTLS: When certificate authentication is done wrong
Implementation flaws in mutual-TLS client authentication: servers that scan the whole certificate chain instead of only the first entry let an attacker impersonate another user with a self-signed certificate (Keycloak); certificate stores build LDAP filters from the unverified Subject field (Bouncy Castle); and revocation URLs read from certificate extensions give SSRF and leak the server's LDAP credentials (Apereo CAS).
Record
- Researcher
- Michael Stepankin
- Published by
- The GitHub Blog
- Date
- Topic
- Identity
In the archive
Related sources
- his blog post
- mTLS: When Certificate Authentication is Done Wrong
- DEF CON 31 - mTLS When Certificate Authentication Done Wrong Michael Stepankin
Tags
This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .