1. Executive Summary & PKI Architecture
Public Key Infrastructure (PKI) underpins trust in modern web operations through X.509 digital certificates issued by trusted Certificate Authorities (CAs). For government portals, financial gateways, and critical digital infrastructure, improper certificate lifecycle management leads to catastrophic outages, expired certificate warnings that deter citizens, or man-in-the-middle (MitM) vulnerabilities caused by unrevoked compromised keys.
2. Inspecting Live Certificates & Chains with OpenSSL
Security auditors must inspect certificate metadata directly from live endpoints without relying exclusively on graphical browser interfaces.
A. Extracting Certificate Expiry and Subject Details
B. Verifying Subject Alternative Names (SAN)
Modern web standards ignore the Common Name (CN) and require all target domains and subdomains to be explicitly enumerated in the Subject Alternative Name (SAN) extension:
C. Verifying Intermediate Certificate Chain Completeness
A common configuration error is serving only the leaf certificate without the intermediate CA bundle. While some desktop browsers cache intermediate certificates, mobile devices and command-line HTTP clients will fail with certificate signed by unknown authority.
3. Auditing OCSP Stapling & Revocation Status
When a private key is compromised or a certificate is re-issued, revocation notices must propagate immediately. Traditional Certificate Revocation Lists (CRLs) require large downloads, while un-stapled Online Certificate Status Protocol (OCSP) slows down initial handshakes and introduces user privacy concerns.
OCSP Stapling (RFC 6066) solves this by having the web server periodically query the CA's OCSP responder and include a cryptographically signed time-stamped status directly within the initial TLS handshake.
Testing OCSP Stapling Status
Audit Rule: If OCSP response: no response sent is returned, OCSP Stapling is not enabled on the server, increasing client-side handshake latency.
4. Automated Renewal Workflows (ACME & Certbot)
Industry CA/Browser Forum baselines have shortened certificate validity periods to 90 days. Manual renewals introduce substantial risk of human error and outages. Production servers must automate certificate issuance and deployment using the ACME protocol.
5. Certificate Lifecycle Audit Checklist
| Audit Metric | Standard Requirement | Pass Criteria |
|---|---|---|
| Remaining Validity | Alerting threshold ≥ 30 days prior to expiration | Certificate does not expire within standard monitoring window |
| Public Key Algorithm & Size | RSA ≥ 2048-bit (4096-bit recommended) or ECC ≥ 256-bit | Zero 1024-bit RSA keys detected |
| Signature Hash Algorithm | SHA-256 or SHA-384 signature algorithm | Zero SHA-1 or MD5 intermediate/leaf signatures |
| Chain Completeness | Full intermediate chain delivered by server | External validator confirms no missing intermediate certificates |
| OCSP Stapling | Server delivers valid, signed OCSP response in handshake | openssl s_client -status returns Cert Status: good |
WebOTG Security Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.