5 ms·
No, but ownership of a.com heavily implies ownership of (wildcard).a.com (HN is being weird with the asterisk) Alternatively they could just do a DNS check. If
by tokenizerrr 9y ago
No, but ownership of a.com heavily implies ownership of (wildcard).a.com (HN is being weird with the asterisk)
Alternatively they could just do a DNS check. If you can configure DNS for a.com, you control *.a.com.
- cyphar 9y ago> heavily implies ownership "heavily implies" is too low of a bar to make it safe for a CA to provide wildcard certificates through an entirely automated process. While they could do it, they care enough about security to make the decision not to. > If you can configure DNS for a.com, you control *.a.com. This assumes that if you can create a TXT record for a.com that you must also have access to the ability to create other records for a.com. While it is a stretch, I would say that the only bar sufficiently high would be fulfilled is forcing an administrator to prove that they can change the NS records for a domain. Which I don't believe would be a practical thing to test, and might run into problems with things like cloudflare.
- tokenizerrr 9y ago> This assumes that if you can create a TXT record for a.com that you must also have access to the ability to create other records for a.com. Yup! And LE is totally fine with this! Have you read the ACME DNS verification spec?