%% You should probably cite draft-ietf-trans-threat-analysis-16 instead of this revision. @techreport{ietf-trans-threat-analysis-00, number = {draft-ietf-trans-threat-analysis-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-trans-threat-analysis/00/}, author = {Stephen Kent}, title = {{Threat Analysis for Certificate Transparency}}, pagetotal = 18, year = 2015, month = jun, day = 3, abstract = {This document describes a threat model for the Web PKI context in which security mechanisms to detect mis-issuance of web site certificates will be developed. The threat model covers both syntactic and semantic mis-issuance, using a taxonomy of threats starting with whether the mis-issuance was done by the CA maliciously or not; then whether or not the certificate was logged; and then whether the log(s) or monitor(s) are benign or malicious, whether the certificate subject is self-monitoring and whether a client is doing any checks.}, }