Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

SP 1800-16(Draft)

Securing Web Transactions: TLS Server Certificate Management

Date Published: July 2019
Comments Due: September 13, 2019 (public comment period is CLOSED)
Email Questions to: tls-cert-mgmt-nccoe@nist.gov

Author(s)

Murugiah Souppaya (NIST), William Haag (NIST), Paul Turner (Venafi), William Barker (Dakota Consulting)

Announcement

This project is using commercially available technologies to develop a cybersecurity reference design that demonstrates how to establish, assign, change and track an inventory of Transport Layer Security (TLS) certificates in medium and large enterprises. Improper oversight of TLS server certificates--which can number into the thousands for a single organization--can cause system outages and security breaches, which can result in revenue loss, harm to reputation, and exposure of confidential data to attackers. 

The public comment period is open until September 13, 2019. We will use this feedback to help shape the final version of this guide. We believe that organizations that adopt NIST's recommended best practices surrounding the oversight of large scale TLS server certificates will strengthen their cybersecurity posture by implementing a plan that helps them better protect their data, privacy and web operations.

NOTE: A call for patent claims is included on page v of Volume B. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Abstract

Keywords

authentication; certificate; cryptography; identity; key; key management; PKI; private key; public key; public key infrastructure; server; signature; TLS; Transport Layer Security
Control Families

Access Control; Audit and Accountability; Configuration Management; Program Management; System and Information Integrity;

Documentation

Publication:
Draft SP 1800-16 volumes and Project Homepage

Supplemental Material:
Submit Comments (other)

Related NIST Publications:
White Paper

Document History:
11/29/18: SP 1800-16 (Draft)
07/17/19: SP 1800-16 (Draft)