5 ms·
That SO post makes no sense to me. It claims: > The authentication test can't merely back down one level to mysub.example.com because that isn't covered by the
by tokenizerrr 9y ago
That SO post makes no sense to me. It claims:
> The authentication test can't merely back down one level to mysub.example.com because that isn't covered by the cert requested, and may not be under the control of the requesting agent either.
This just seems wrong. Performing the check like that seems to be a sane way to do it. If people can't control the base domain they have no business requesting a wildcard cert.
- cyphar 9y agoBut *.a.com doesn't cover a.com, so it's not very clear that the inverse ownership relationship should hold. Yes, it's true on a DNS level but that's one argument I would imagine against doing it that way.
- tokenizerrr 9y agoNo, but ownership of a.com heavily implies ownership of (wildcard).a.com (HN is being weird with the asterisk) Alternatively they could just do a DNS check. If you can configure DNS for a.com, you control *.a.com.
- cyphar 9y ago> heavily implies ownership "heavily implies" is too low of a bar to make it safe for a CA to provide wildcard certificates through an entirely automated process. While they could do it, they care enough about security to make the decision not to. > If you can configure DNS for a.com, you control *.a.com. This assumes that if you can create a TXT record for a.com that you must also have access to the ability to create other records for a.com. While it is a stretch, I would say that the only bar sufficiently high would be fulfilled is forcing an administrator to prove that they can change the NS records for a domain. Which I don't believe would be a practical thing to test, and might run into problems with things like cloudflare.
- tokenizerrr 9y ago> This assumes that if you can create a TXT record for a.com that you must also have access to the ability to create other records for a.com. Yup! And LE is totally fine with this! Have you read the ACME DNS verification spec?
- eropple 9y agoI regularly have subdomain zones delegated to AWS for Route 53 use without having direct control over the root domain. The idea that I must have direct control to assert control over a subdomain is pretty questionable.
- tokenizerrr 9y agoIf you don't have access, fine. You can't make use of this functionality. Stick with what is available today. Nothing lost. If you do have access, like 99% of the domains out there, you now get access to more functionality. Win-win.
- deleted 9y ago[deleted]