4 ms·
IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
by ponytech 11y ago
IMO the problem is more "attackers who have gained the ability to create subdomains under a legitimate domain" (not explained how) than Let's Encrypt.
- qopp 11y agoThere are sites that do this as part of their core ui, such as deviantart.
- alexpeattie 11y agoYes, although the subdomains still point to deviantart's servers. The difference here is that ad.example.com ends up pointing to the attacker's server. Because LetsEncrypt needs a very specific response to be served from a specific endpoint, you need this kind of total control to validate a domain and get a certificate issued.
- rmhrisk 11y agosee: https://publicsuffix.org/ https://publicsuffix.org/
- nulagrithom 11y agohttps://letsencrypt.org/howitworks/technology/#domain-validation https://letsencrypt.org/howitworks/technology/#domain-valida... There's a bit more to it than "allowing subdomain creation". You will need control over the DNS records, or ability arbitrarily change the page (essentially).