Current PKIX infrastructure for TLS is prone to MITM attacks, which are usually consummated
by the use of forged certifi cates or by manipulating certifi cate path validation. IETF and other
standardization bodies have launched several initiatives to enable the detection of “forged”
certifi cates. Most of the proposals focus on minimizing the impact of certifi cate misissuance
while maintaining the current PKI model almost unchanged in order to ensure compatibility,
usability and low-cost deployment.