Comodo is communicating actively in the bug, in the email discussion, and proactively CC'd the original reporter on the bug that was filed about this without being asked to do so. The general rule in Operations work is tolerance. You don't fire someone for making a mistake, you fire them for lying about the mistake, for refusing to avoid mistake-prone behaviors, and other problem of that sort. Applying that same prin…
I would bet money (maybe not a lot of money, but money) that the only outcome of this is that Comodo ends up within a month being the CA that most reliably checks CAA records. It would be shocking if Google penalized them for this. As you say, that's based in part on how they handle it.
Comodo fails to check CAA records
41–50 of 71 posts
Re: Comodo fails to check CAA records
#42 $ dig empty.basic.caatestsuite.com type257
More resources here:Re: Comodo fails to check CAA records
#43Re: Comodo fails to check CAA records
#44This inspired me to add a CAA record for my domain - but https://www.namecheap.com doesn't support that record type. Has anyone had better luck other places?
Re: Comodo fails to check CAA records
#45This inspired me to add a CAA record for my domain - but https://www.namecheap.com doesn't support that record type. Has anyone had better luck other places?
Re: Comodo fails to check CAA records
#46If you're not already familiar with his work, you should know that Hanno Böck is a machine, and someone worth following. If there's some mistake you can make with the web PKI that is so stupid nobody would ever bother to check for it, rest assured that Hanno will eventually check.
Re: Comodo fails to check CAA records
#47Earlier quoted context omitted.
I would bet money (maybe not a lot of money, but money) that the only outcome of this is that Comodo ends up within a month being the CA that most reliably checks CAA records. It would be shocking if Google penalized them for this. As you say, that's based in part on how they handle it.
The thing I'm sad to see is that there's no third-party information stated on when Comodo's CAA verification started and stopped. When they first announced CAA support, who tested it? When did it stop working? So I'm hoping this will come out of the post-mortem and be shared with us all.
Re: Comodo fails to check CAA records
#48Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.
CAA was made up by... drumroll.... Comodo.
Yes, check the authors on the RFC: https://tools.ietf.org/html/rfc6844
Re: Comodo fails to check CAA records
#49Earlier quoted context omitted.
>working with a malware company Why is this a bad thing? A cert says "Yes, person x REALLY IS person x, and I can prove it mathematically." It doesn't say "Person x is trustworthy enough for me to vouch for them."
Who do you imagine they verified was Person X? More on the malware cert issuance: https://blogs.msmvps.com/donna/2009/05/18/microsoft-mvp-mike... For malware concerns there's also Comodo's relationship with PrivDog. I'm not clear on whether PrivDog is deliberate malware or just incompetent insecure software.
Do you think we should stop allowing Let's Encrypt to issue certs? You know they don't google each domain to see what they are doing.
Re: Comodo fails to check CAA records
#50This inspired me to add a CAA record for my domain - but https://www.namecheap.com doesn't support that record type. Has anyone had better luck other places?
You may find my CAA website helpful: https://sslmate.com/caa/support