Live data from Hacker News

DigiCert Revocation Incident (CNAME Domain Validation)

digicert.com

21–30 of 56 posts

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#21
post #19

Earlier quoted context omitted.

What critical support information? What global outage? How are these two events or companies remotely equivalent? If I'm not a Digicert customer, what do I care about the details of how to redo a validation on Digicert? If I am a Digicert customer I have been emailed already and I will obviously have to log in to do anything at all with my domain. They say this affects 0.4% of Digicert customers who are what % of the…

[deleted]

[deleted]

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#23

Earlier quoted context omitted.

Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

There are.

There shouldn't be, but there are.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#24

I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.

If you’re not a customer, your domain isn’t affected.

You may be a customer of a customer (e.g. Azure) so you could be affected peripherally via that route.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#25
post #20

Is this a potential cause of the current Azure outages hitting western europe? I know DigiCert are used by Azure extensively...

Unlikely. Microsoft operates their own CAs. Some of their CAs have been cross-signed by a DigiCert root, but Microsoft is responsible for the domain validation. I don't think they extensively use certificates issued directly by a DigiCert CA.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#26

Earlier quoted context omitted.

Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

Google also indexed my site http://_.4a.si as seen here http://google.com/search?q=site:_.4a.si

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#27
post #14

24h notice to change certificates in who knows how many systems, at the worlds largest companies, while everyone is on vacation. This will be interesting.

Respect to them for actually abiding by the BRs. Most CAs just shrug [1] and [2] say [3] it's [4] too [5] complicated [6], or just lie and claim planes will start crashing [7]. It's really disheartening that publicly trusted CAs just ignore their contractual obligations however they see fit.

Ideally these companies should have response plans in place to prioritize certificate rotation. They can use this as a fire drill for what would happen if there were a key compromise.

Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case.

[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1885568

[2]: https://bugzilla.mozilla.org/show_bug.cgi?id=1898848

[3]: https://bugzilla.mozilla.org/show_bug.cgi?id=1910237

[4]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896053

[5]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896553

[6]: https://bugzilla.mozilla.org/show_bug.cgi?id=1877388

[7]: https://bugzilla.mozilla.org/show_bug.cgi?id=1903066#c48

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#28

Earlier quoted context omitted.

Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

In 2019 the CAs agreed not to issue certs to underscored subdomains making this less useful.

As evidenced by all your links being http.

(as an aside, it looks really weird seeing a bare http link in the wild - crazy that was the old norm!)

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#29

Earlier quoted context omitted.

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

Google also indexed my site http://_.4a.si as seen here http://google.com/search?q=site:_.4a.si

A live proof that CNAME records starting with _ exist.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#30
post #28

Earlier quoted context omitted.

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

In 2019 the CAs agreed not to issue certs to underscored subdomains making this less useful. As evidenced by all your links being http. (as an aside, it looks really weird seeing a bare http link in the wild - crazy that was the old norm!)

My browser is configured to auto-upgrade such links and I get a full screen interstitial when the upgrade fails (as of course it did for these)

This is now at a place where I'd recommend such configuration more broadly, it's not suitable for everybody, but many could benefit from just knowing all links are secured.

Post reply on HN