5 ms·
The underlying issue here is that WHOIS is still not standardised despite being around for over 30 years, and the registrars do not have any other common interf
by longwave 10y ago
The underlying issue here is that WHOIS is still not standardised despite being around for over 30 years, and the registrars do not have any other common interface that can be used to discover domain owners and other metadata. Is there no workable solution to this problem?
- nailer 10y ago> the registrars do not have any other common interface that can be used to discover domain owners and other metadata There's `.well-known` HTTP resources: https://tools.ietf.org/html/rfc5785 https://tools.ietf.org/html/rfc5785 I work for CertSimple and we automatically use `(site)/.well-known/pki-validation` if we see whois privacy, because in practice customers using whois privacy are inevitably uncontactible. We may use `.well-known` by default in future. Our friends at LE/Certbot (ie, ACME) use `(site)/.well-known/acme-challenge`. Also there is various efforts to replace/standardize whois, eg WEIRD and RDAP https://tools.ietf.org/html/rfc7483 https://tools.ietf.org/html/rfc7483. However .well-known resources work well enough for the purposes and in practice is more widely used.
- stephenr 10y agoSo if WHOIS has the correct (matching) business name, you trust that, presumably?
- nailer 10y agoNo. Whois isn't used for identifying legal entities (EV). Just for proving control over a domain (baseline requirements).
- stephenr 10y agoSorry what I meant is proving control of the domain by the specified legal entity. If I apply for an ev cert for ACME Inc to use on acme.com and have "ACME Inc" as the registered owner in Whois, does that satisfy the domain control check?
- geofft 10y agoEV doesn't necessarily promise "this company owns this domain", does it? I thought it says "the certificate holder is this company" + "the certificate holder controls this domain" (which is the standard DV check). Which is all I want, anyway. If I'm typing my Bank of America login info, I care that it's being encrypted to a private key in Bank of America's control, and it doesn't really matter if that happens through a DNS name registered to Bank of America or not. It would be weird if it didn't, but it wouldn't inherently impact my security if the key was still BoA's.
- iancarroll 10y agoYes, your understanding is correct, though a CA can use domain ownership to skip DV checks (if you validate requester is X Inc and X Inc is listed in WHOIS, no DCV needed).
- nailer 10y agoUnderstood, but that's still not correct. Whois is Only used for proving control by whatever contact is mentioned in Whois. The company name in Whois isn't used for EV verification of legal entities at all.
- stephenr 10y agoThanks for the clarification!
- djsumdog 10y agoThat's also what LetsEncrypt uses as well via the ACME protocol
- orf 10y agoWhat percentage of sites use .well-known?
- eridius 10y agoWhy isn't .well-known/pki-validation in the Well-Known URI registry? https://www.iana.org/assignments/well-known-uris/well-known-uris.xhtml https://www.iana.org/assignments/well-known-uris/well-known-...
- tialaramex 10y agoProbably someone needs to ask IANA to do so. As far as I know (and I'm happy to learn otherwise) the first mention of .well-known/pki-validation was Ballot 169 https://cabforum.org/2016/08/05/ballot-169-revised-validation-requirements/ https://cabforum.org/2016/08/05/ballot-169-revised-validatio... to the CA/B forum. It is possible that the people drafting that ballot didn't feel they ought to approach IANA until after it was voted through, and then they simply forgot. It is also possible that the subsequent IP fuss (a bunch of CA/B members turn out to have patented some methods listed in Ballot 169) distracted everybody Finally it's possible IANA just didn't get around to updating the list yet.
- geofft 10y agoIf you're willing to go for "current control of the domain" instead of "owner" (and in practice we are, because a ton of CAs including Let's Encrypt allow that), there's hitting /.well-known/ via HTTP, as 'nailer points out, and there's also emailing admin@, administrator@, webmaster@, hostmaster@, or postmaster@ the domain, as explicitly permitted by the CA/Browser Forum baseline requirements (3.2.2.4 #4).
- revelation 10y agoNo, that's not the issue at all. CAs like Comodo are paid very handsomely for what is essentially a zero marginal cost item. It is not the problem of WHOIS that they want to skate their responsibilities and think some rent-a-coder OCR bullshit is an adequate solution.
- kijeda 10y agoThere is. There is a relatively new IETF standard called RDAP that provides JSON-structured WHOIS data responses (i.e. https://tools.ietf.org/html/rfc7483 https://tools.ietf.org/html/rfc7483) along with automatic discovery. ICANN is working on making it a mandate for gTLDs to support it. It is already supported for IP address lookups by all 5 regional Internet registries.
- robalfonso 10y agoActually as of 2013 - ICANN required registrars on the latest contract to standardize whois output, further next year a new protocol RDAP will be available that will add to this. So I'd say their are much more workable solutions here and more coming soon.