Ssl.com: DCV bypass and issue fake certificates for any MX hostname
bugzilla.mozilla.org
Ssl.com: DCV bypass and issue fake certificates for any MX hostname
1–10 of 66 posts
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#2But at least it initially appears SSL.com is taking it seriously, we'll have to see what the report says.
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#3Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#4I guess they can check logs and find how many times this has been abused already? Can we trust them to release full transparent report?
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#5Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#6Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#7So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.
Issuing a Google certificate is a good way to get your whole CA killed.
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#8So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#9Have they started revoking invalid certs?
Re: Ssl.com: DCV bypass and issue fake certificates for any MX hostname
#10So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.
Even then, use of a DNS CAA record should mitigate this, right?