Related work
The issues with SSL and the CA trust model have been known for years, and various proposals have appeared in the literature, suggesting to replace, amend, or comple- ment the current system. Laribus is a combination and extension of techniques selected from the current stateof the art. It does not replace the existing PKI infrastruc- ture but serves as an additional source of trust during certificate validation.
This section provides an overview of the most impor- tant research directions, outlining their benefits and limi- tations. A comprehensive discussion of previous work can be found in [14,15].
In Sections 2.1 and 2.2, we describe approaches that advocate to restrict the domains a CA may issue certifi- cates for. In Section 2.3, we describe the trust on first use model. We proceed with proposals that rely on out-of- band information for certificate validation in Section 2.4. Another avenue of research focuses on the application of append-only data structures (cf. Section 2.5). Finally, in Section 2.6, we discuss existing work that relies on notaries that provide clients with a third-party perspective of a certificate.