DigiCert .arpa Mis-Issuance
groups.google.com
DigiCert .arpa Mis-Issuance
1–8 of 8 posts
Re: DigiCert .arpa Mis-Issuance
#2However, since issuing for .arpa is weird (and maybe should be forbidden), the discussion got sidetracked talking about .arpa issuance.
DigiCert's analysis of the vulnerability can be found here: https://groups.google.com/d/msg/mozilla.dev.security.policy/...
Re: DigiCert .arpa Mis-Issuance
#3To be clear, the failure here is not that DigiCert issued for .arpa, which is not forbidden, but that they gave the reporter, Cynthia Revström, the ability to issue for all of in-addr.arpa even though she had only demonstrated control over 5.168.110.79.in-addr.arpa. This vulnerability could have applied to regular non-arpa domains too; e.g. someone with control over example.github.io might have been able to get a cer…
Re: DigiCert .arpa Mis-Issuance
#4To be clear, the failure here is not that DigiCert issued for .arpa, which is not forbidden, but that they gave the reporter, Cynthia Revström, the ability to issue for all of in-addr.arpa even though she had only demonstrated control over 5.168.110.79.in-addr.arpa. This vulnerability could have applied to regular non-arpa domains too; e.g. someone with control over example.github.io might have been able to get a cer…
I think that, realistically, that's a lot less likely. I think the "weirdness" of the in-addr.arpa hierarchy contributed to the "manual validators" just shrugging and pushing through.
I think the main issue raised is that whois record checking is becoming manual and silly because of whois throttling and captchas and GDPR concerns ... in many cases it's not really working well enough to issue certificates based on.
Re: DigiCert .arpa Mis-Issuance
#5To be clear, the failure here is not that DigiCert issued for .arpa, which is not forbidden, but that they gave the reporter, Cynthia Revström, the ability to issue for all of in-addr.arpa even though she had only demonstrated control over 5.168.110.79.in-addr.arpa. This vulnerability could have applied to regular non-arpa domains too; e.g. someone with control over example.github.io might have been able to get a cer…
Re: DigiCert .arpa Mis-Issuance
#6To be clear, the failure here is not that DigiCert issued for .arpa, which is not forbidden, but that they gave the reporter, Cynthia Revström, the ability to issue for all of in-addr.arpa even though she had only demonstrated control over 5.168.110.79.in-addr.arpa. This vulnerability could have applied to regular non-arpa domains too; e.g. someone with control over example.github.io might have been able to get a cer…
I am very much aware, because I am indeed that reporter, but I just didn't want to change the title from the email subject
Re: DigiCert .arpa Mis-Issuance
#7Earlier quoted context omitted.
I am very much aware, because I am indeed that reporter, but I just didn't want to change the title from the email subject
Great example of vigilence here. I can’t see anything in your report that would lead me to think this only happened to you, but you seem to be the first to notice and follow through on the hunch. Nice work!
Re: DigiCert .arpa Mis-Issuance
#8To be clear, the failure here is not that DigiCert issued for .arpa, which is not forbidden, but that they gave the reporter, Cynthia Revström, the ability to issue for all of in-addr.arpa even though she had only demonstrated control over 5.168.110.79.in-addr.arpa. This vulnerability could have applied to regular non-arpa domains too; e.g. someone with control over example.github.io might have been able to get a cer…
> someone with control over example.github.io might have been able to get a certificate for any github.io domain I think that, realistically, that's a lot less likely. I think the "weirdness" of the in-addr.arpa hierarchy contributed to the "manual validators" just shrugging and pushing through. I think the main issue raised is that whois record checking is becoming manual and silly because of whois throttling and ca…