3 ms·
There are sites that do this as part of their core ui, such as deviantart.
by qopp 11y ago
There are sites that do this as part of their core ui, such as deviantart.
- alexpeattie 11y agoYes, although the subdomains still point to deviantart's servers. The difference here is that ad.example.com ends up pointing to the attacker's server. Because LetsEncrypt needs a very specific response to be served from a specific endpoint, you need this kind of total control to validate a domain and get a certificate issued.
- rmhrisk 11y agosee: https://publicsuffix.org/ https://publicsuffix.org/
- nulagrithom 11y agohttps://letsencrypt.org/howitworks/technology/#domain-validation https://letsencrypt.org/howitworks/technology/#domain-valida... There's a bit more to it than "allowing subdomain creation". You will need control over the DNS records, or ability arbitrarily change the page (essentially).