"Setting up TLS authentication was hell": A Usability Study of Client Certificate Authentication
arXiv:2604.14330
Abstract
"Cryptography turns a security problem into a key management problem." Despite decades of research effort towards usable key management, it remains unclear whether key management issues are inherent to every cryptographic system or merely artifacts of specific designs. To investigate, this paper presents a user study of mutual TLS (mTLS) usability, tracking 46 senior and graduate computer science students, highly technical users who configured client certificates, used them for routine authentication over a semester-long course, and managed credentials across multiple devices. Our results show that initial setup and setting up credentials on a second device are difficult, while routine authentication is easy once configured. Nevertheless, perceived usability remained low, and alarmingly, only 9 percent of participants fully understood mTLS security implications and key management. Our findings demonstrate that usability challenges shift across the credential lifecycle depending on system architecture. We conclude by offering design recommendations for future key management systems to better support users across the complete credential lifecycle.
This is an extended version of the paper accepted at the 2026 ACM SIGSAC Conference on Computer and Communications Security (ACM CCS 2026). 19 pages, 5 figures, and 7 tables