Earlier quoted context omitted.
What critical support information? What global outage? How are these two events or companies remotely equivalent? If I'm not a Digicert customer, what do I care about the details of how to redo a validation on Digicert? If I am a Digicert customer I have been emailed already and I will obviously have to log in to do anything at all with my domain. They say this affects 0.4% of Digicert customers who are what % of the…
[deleted]
DigiCert Revocation Incident (CNAME Domain Validation)
21–30 of 56 posts
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#22Re: DigiCert Revocation Incident (CNAME Domain Validation)
#23Earlier quoted context omitted.
Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…
So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…
There shouldn't be, but there are.
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#24I just want to call out both CrowdStrike and DigiCert for being one of "those" companies that insist on publishing critical support information behind a login with the clock ticking on a global outage of their own making. There are no polite words that I can use to accurately convey the depth of my disappointment at this kind of inconsiderate behaviour during a crisis, so I won't say anything more.
If you’re not a customer, your domain isn’t affected.
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#25Is this a potential cause of the current Azure outages hitting western europe? I know DigiCert are used by Azure extensively...
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#26Earlier quoted context omitted.
Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…
So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#2724h notice to change certificates in who knows how many systems, at the worlds largest companies, while everyone is on vacation. This will be interesting.
Ideally these companies should have response plans in place to prioritize certificate rotation. They can use this as a fire drill for what would happen if there were a key compromise.
Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1885568
[2]: https://bugzilla.mozilla.org/show_bug.cgi?id=1898848
[3]: https://bugzilla.mozilla.org/show_bug.cgi?id=1910237
[4]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896053
[5]: https://bugzilla.mozilla.org/show_bug.cgi?id=1896553
[6]: https://bugzilla.mozilla.org/show_bug.cgi?id=1877388
[7]: https://bugzilla.mozilla.org/show_bug.cgi?id=1903066#c48
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#28Earlier quoted context omitted.
Also, while a DNS name can have an underscore a host name, even in DNS, cannot have this character. So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. So even if you are completely oblivious to this work, and don't care about security at all, your "Give everybody a hostnam…
So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…
As evidenced by all your links being http.
(as an aside, it looks really weird seeing a bare http link in the wild - crazy that was the old norm!)
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#29Earlier quoted context omitted.
So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…
Google also indexed my site http://_.4a.si as seen here http://google.com/search?q=site:_.4a.si
Re: DigiCert Revocation Incident (CNAME Domain Validation)
#30Earlier quoted context omitted.
So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…
In 2019 the CAs agreed not to issue certs to underscored subdomains making this less useful. As evidenced by all your links being http. (as an aside, it looks really weird seeing a bare http link in the wild - crazy that was the old norm!)
This is now at a place where I'd recommend such configuration more broadly, it's not suitable for everybody, but many could benefit from just knowing all links are secured.