Live data from Hacker News

Comodo fails to check CAA records

mail-archive.com

41–50 of 71 posts

Re: Comodo fails to check CAA records

#41
post #35

Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so. The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort. Applying that same prin…

I would bet money (maybe not a lot of money, but money) that the only outcome of this is that Comodo ends up within a month being the CA that most reliably checks CAA records. It would be shocking if Google penalized them for this. As you say, that's based in part on how they handle it.

The thing I'm sad to see is that there's no third-party information stated on when Comodo's CAA verification started and stopped. When they first announced CAA support, who tested it? When did it stop working? So I'm hoping this will come out of the post-mortem and be shared with us all.

Re: Comodo fails to check CAA records

#42
If this is the first time you've heard of CAA records, note that the "dig" command isn't yet aware of these records types, so you need to tell it to use "type257" as the record type:

    $ dig empty.basic.caatestsuite.com type257
More resources here:

https://support.dnsimple.com/articles/caa-record/

https://caatestsuite.com/

Re: Comodo fails to check CAA records

#46
post #34

If you're not already familiar with his work, you should know that Hanno Böck is a machine, and someone worth following. If there's some mistake you can make with the web PKI that is so stupid nobody would ever bother to check for it, rest assured that Hanno will eventually check.

Yes!

Re: Comodo fails to check CAA records

#47
post #35

Earlier quoted context omitted.

I would bet money (maybe not a lot of money, but money) that the only outcome of this is that Comodo ends up within a month being the CA that most reliably checks CAA records. It would be shocking if Google penalized them for this. As you say, that's based in part on how they handle it.

The thing I'm sad to see is that there's no third-party information stated on when Comodo's CAA verification started and stopped. When they first announced CAA support, who tested it? When did it stop working? So I'm hoping this will come out of the post-mortem and be shared with us all.

Comodo is required by Mozilla to publish a public incident report: https://wiki.mozilla.org/CA/Responding_To_A_Misissuance

Re: Comodo fails to check CAA records

#48

Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.

> Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs?

CAA was made up by... drumroll.... Comodo.

Yes, check the authors on the RFC: https://tools.ietf.org/html/rfc6844

Re: Comodo fails to check CAA records

#49

Earlier quoted context omitted.

>working with a malware company Why is this a bad thing? A cert says "Yes, person x REALLY IS person x, and I can prove it mathematically." It doesn't say "Person x is trustworthy enough for me to vouch for them."

Who do you imagine they verified was Person X? More on the malware cert issuance: https://blogs.msmvps.com/donna/2009/05/18/microsoft-mvp-mike... For malware concerns there's also Comodo's relationship with PrivDog. I'm not clear on whether PrivDog is deliberate malware or just incompetent insecure software.

That is ridiculous, to expect a CA to google every cert request domain and check what they are doing? That is a ridiculous requirement - cert issuance is automatic.

Do you think we should stop allowing Let's Encrypt to issue certs? You know they don't google each domain to see what they are doing.

Re: Comodo fails to check CAA records

#50
post #44

This inspired me to add a CAA record for my domain - but https://www.namecheap.com doesn't support that record type. Has anyone had better luck other places?

You may find my CAA website helpful: https://sslmate.com/caa/support

I used your site - it was quick and easy. It soon went downhill from there. I don't run my own DNS or I'd be done pasting the line into my config. Instead I ran into a UI that doesn't support CAA as a type.
Post reply on HN