Quantcast
Viewing all articles
Browse latest Browse all 50

Comment by R.. GitHub STOP HELPING ICE on Can a powerful adversary trick ACME to generate a certificate?

The CAA record can also mandate use of DNS-01 (disallowing HTTP-01) ACME method, at least if LE has enabled that in production yet. Combined with DNSSEC, this makes it cryptographically impossible for a CA honoring the requirement to check CAA to issue a certificate to the attacker, unless the attacker has already managed to coerce a fraudulent DS record to be installed at some level of the DNS hierarchy.

Viewing all articles
Browse latest Browse all 50

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>