Live data from Hacker News

DigiCert Revocation Incident (CNAME Domain Validation)

digicert.com

51–56 of 56 posts

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#51

Earlier quoted context omitted.

> Stuff like this is why some parties have been calling for increasingly-shorter cert validity. When a cert is valid for several years it allows companies to develop an increasingly complex workflow around deploying them, sometimes taking weeks and involving dozens of parties to roll them out. This is in turn used as an excuse by CAs to completely ignore the industry standards. "several years"? The certs we are getti…

I work with customers that typically take 3 or 4 days to either acquire or renew a cert. Even though they are on one of the major cloud provider with automated certs, they refuse to use those mechanisms due to policy. They would rather send everything, including private keys, through email. They also take several days, sometimes weeks, to update a DNS entry. Welcome to modern IT.

Trying to deploy SaaS apps for customers it sometimes takes 3-4 weeks to get them to make any DNS changes, then at the last minute they CC us into an email with SquareSpace support for some reason (their DNS is on Cloudflare...)

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#52

Can someone explain why this issue deserves a 24h notice? Seems more reasonable to me to have a much longer deprecation notice.

As far as I can tell, this issue would be a problem where all of the following conditions are met:

1. Tenants are allowed to create arbitrary subdomains with arbitrary CNAME values 2. Tenants are not authorized to act on behalf of the TLD directly, only on their respective subdomain 3. Tenants are ostensibly prevented from TLD cert issuance by being explicitly blocked from creating subdomains that start with underscores

For most entities these conditions probably do not hold true anyway. But it could conceivably apply to certain free/dynamic dns providers, for example afraid.org and noip both allow arbitrary CNAMEs (though I checked my noip account and it wouldn't work anyway because of length limits on subdomains).

I would guess that in act fact there are very few entities in existence for which this actually represents a potential threat against them, since it requires a very specific delineation of zone authorizations, but there might be a few.

For most of Alegeus customers I doubt any of this applies, though, they're probably lucky to know their GoDaddy login to add any sort of DNS record, let alone have a whole system in place for less privileged users to create arbitrary CNAME records subject to controls over the use of underscores.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#53
post #28

Earlier quoted context omitted.

So if you have a user named "haha_funny" you already aren't allowed to give them the hostname "haha_funny.somesite.example" - and on some system it will just silently not work because it's invalid. Not long ago I actually did come across a site that had an underscore in its domain name, and it worked both for me and apparently Google, because it indexed and showed a (relevant) page from that site. I only remembered i…

In 2019 the CAs agreed not to issue certs to underscored subdomains making this less useful. As evidenced by all your links being http. (as an aside, it looks really weird seeing a bare http link in the wild - crazy that was the old norm!)

Wildcard certs match subdomains with underscores, as pointed out by a sibling comment. Example: https://_.4a.si./

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#54

Earlier quoted context omitted.

I work with customers that typically take 3 or 4 days to either acquire or renew a cert. Even though they are on one of the major cloud provider with automated certs, they refuse to use those mechanisms due to policy. They would rather send everything, including private keys, through email. They also take several days, sometimes weeks, to update a DNS entry. Welcome to modern IT.

Trying to deploy SaaS apps for customers it sometimes takes 3-4 weeks to get them to make any DNS changes, then at the last minute they CC us into an email with SquareSpace support for some reason (their DNS is on Cloudflare...)

I believe it. It's insane how long some of this stuff takes.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#55
post #35

Earlier quoted context omitted.

Stuff like this is why some parties have been calling for increasingly-shorter cert validity. When a cert is valid for several years it allows companies to develop an increasingly complex workflow around deploying them, sometimes taking weeks and involving dozens of parties to roll them out. This is in turn used as an excuse by CAs to completely ignore the industry standards. Those SaaS vendors probably shouldn't be…

I think the issue is less with SaaS vendors doing cert pinning and more that many SaaS vendors offering deploying on customer domains often rely on those same customers to make the DNS changes for validation, and whenever you introduce another party like that it's exponentially more difficult to actually get things done in a timely matter. IMO they should just use HTTP challenges to avoid this whole thing, but it's a…

That's one option. Alternatively, they could just delegate the _acme-challenge with a CNAME.

If clientportal.somebank.com is actually run by somesaas.com, they can define CNAME _acme-challenge.clientportal.somebank.com --> [some_key].domainvalidations.somesaas.com

When the SaaS vendor needs to request a new cert, they set the appropriate TXT record on [some_key].domainvalidations.somesaas.com.

Re: DigiCert Revocation Incident (CNAME Domain Validation)

#56
post #34
post #32

Earlier quoted context omitted.

"Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case." I hate hearing this awful take, as if every IT organization has the same neat and tidy systems deployed as they do. Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change, don't have any hardware devices or appliance based softwa…

"Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change" I think this tends to fall into "probably shouldn't have been using Web PKI". I can't immediately think of a reason why you'd need a publicly trusted certificate if you're pinning a specific public key.. at that point who cares who signed it? I do agree that there are real costs with rotating certificates that ulti…

Getting your online account hacked can feel like a punch to the gut. It's unsettling and makes you question your digital safety. But don’t worry! Here’s a roadmap to help you recover your hacked account and get back to feeling secure online. she a tech reach her (MARIECONSULTANCYOZ@GMAIL.COM and INSTAGRAM :MARIE_CONSULTANCY)
Post reply on HN