Live data from Hacker News

DigiCert Revocation Incident (CNAME Domain Validation)

digicert.com

11–20 of 56 posts

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#11
post #8
post #5

> The underscore prefix ensures that the random value cannot collide with an actual domain name that uses the same random value. While the odds of that happening are practically negligible, the validation is still deemed as non-compliant if it does not include the underscore prefix. That's not the rationale for mandating the underscore prefix. The actual reason is so services that allow users to create DNS records at…

> For example, if an attacker requests a certificate for dyndns.example Shouldn't that get caught by the Public Suffix List? I would hope DigiCert has checks in place to prevent someone domain-validating ownership of the entire of co.uk under any circumstances :) (They should still revoke the mis-issued certificates though)

> Shouldn't that get caught by the Public Suffix List?

PSL is a best-effort sort of thing, so it's good but not definitive. It would be dangerous to rely on it when issuing certs imo.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#12
post #8
post #5

> The underscore prefix ensures that the random value cannot collide with an actual domain name that uses the same random value. While the odds of that happening are practically negligible, the validation is still deemed as non-compliant if it does not include the underscore prefix. That's not the rationale for mandating the underscore prefix. The actual reason is so services that allow users to create DNS records at…

> For example, if an attacker requests a certificate for dyndns.example Shouldn't that get caught by the Public Suffix List? I would hope DigiCert has checks in place to prevent someone domain-validating ownership of the entire of co.uk under any circumstances :) (They should still revoke the mis-issued certificates though)

PSL has a couple of sections - ICANN and PRIVATE. PRIVATE can be a little more flexible/ignorable. If they implement a hard rule, then occasionally they'd have to make exceptions when the real Dyn comes along and wants (legitimately) a wildcard for their name.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#13
> While we had regression testing in place, those tests failed to alert us to the change in functionality because the regression tests were scoped to workflows and functionality instead of the content/structure of the random value. [...]

> Unfortunately, no reviews were done to compare the legacy random value implementations with the random value implementations in the new system for every scenario.

In other words, they didn't do proper testing. At the bottom of the article they suggest they're going to improve it.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#15
post #8
post #5

> The underscore prefix ensures that the random value cannot collide with an actual domain name that uses the same random value. While the odds of that happening are practically negligible, the validation is still deemed as non-compliant if it does not include the underscore prefix. That's not the rationale for mandating the underscore prefix. The actual reason is so services that allow users to create DNS records at…

> For example, if an attacker requests a certificate for dyndns.example Shouldn't that get caught by the Public Suffix List? I would hope DigiCert has checks in place to prevent someone domain-validating ownership of the entire of co.uk under any circumstances :) (They should still revoke the mis-issued certificates though)

There's no prohibition against issuing certificates for names on the Public Suffix List.

BR 3.2.2.6 prohibits issuing a wildcard certificate for an entire public suffix unless the "Applicant proves its rightful control of the entire Domain Namespace" (without specifying how this should be done - arguably, publishing a DNS record would qualify) but also says that CAs should use the "ICANN DOMAINS" section of the PSL only, not the "PRIVATE DOMAINS" section, so domains for dynamic DNS providers and the like wouldn't be included. [https://github.com/cabforum/servercert/blob/main/docs/BR.md#...]

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#16

I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.

What critical support information? What global outage? How are these two events or companies remotely equivalent?

If I'm not a Digicert customer, what do I care about the details of how to redo a validation on Digicert? If I am a Digicert customer I have been emailed already and I will obviously have to log in to do anything at all with my domain.

They say this affects 0.4% of Digicert customers who are what % of the world? Actually not even 0.4% of Digicert customers, but 0.4% of those particular validations. What does that actually work out to? Just who all is actually down?

I fail to see any equivalence.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#17

I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.

If you’re not a customer, your domain isn’t affected.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#18

I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.

If you’re not a customer, your domain isn’t affected.

[deleted]

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#19

I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.

What critical support information? What global outage? How are these two events or companies remotely equivalent? If I'm not a Digicert customer, what do I care about the details of how to redo a validation on Digicert? If I am a Digicert customer I have been emailed already and I will obviously have to log in to do anything at all with my domain. They say this affects 0.4% of Digicert customers who are what % of the…

[deleted]
Post reply on HN