3 ms·
I can create "773c7d.13445a.acme.invalid" in almost all shared hosting control panels I have access to. When I send an HTTP request with Host: 773c7d.13445a.ac
by paralelogram 9y ago
I can create "773c7d.13445a.acme.invalid" in almost all shared hosting control panels I have access to.
When I send an HTTP request with Host: 773c7d.13445a.acme.invalid, the server responds with a file from ~/domains/773c7d.13445a.acme.invalid/public_html or a similar directory available through my FTP account.
When I connect using openssl s_client ... -servername 773c7d.13445a.acme.invalid, the server sends a certificate configured for 773c7d.13445a.acme.invalid in my control panel.
Is this a problem for Let's Encrypt? Doesn't Let's Encrypt's verification require creating files with random names in http://example.com/.well-known/acme-challenge http://example.com/.well-known/acme-challenge where example.com is the certificate's common name?
- pfg 9y ago> Is this a problem for Let's Encrypt? Doesn't Let's Encrypt's verification require creating files with random names in http://example.com/.well-known/acme-challenge http://example.com/.well-known/acme-challenge where example.com is the certificate's common name? That applies to the http-01 challenge. The tls-sni-01 challenge works solely based on the returned certificate. If the SAN value in the certificate matches the SNI value sent by the validation server, the challenge succeeds. Would you mind sharing which control panel you tested this with?
- paralelogram 9y agoDirectAdmin, the most popular webhosting control panel in my country. In my opinion this is not a bug because when I need to test a website, I often create an invalid hostname on the server and add the server's IP address to my computer's /etc/hosts. When I need HTTPS, I upload a certificate for the test hostname signed by my private CA.
- pfg 9y agoThanks. I signed up for the first shared web hosting provider I could find that uses DirectAdmin and was able to reproduce this. I'll bring this up in the relevant thread on mozilla.dev.security.policy, this is definitely concerning.
- Ajedi32 9y ago> Doesn't Let's Encrypt's verification require creating files with random names in http://example.com/.well-known/acme-challenge http://example.com/.well-known/acme-challenge where example.com is the certificate's common name? Are you asking whether this is an issue for the http-01 challenge? If so, the answer is no, because if you wanted to use this to obtain a cert for some domain you don't own, the DNS reponse for that domain would have to already point to the shared hosting server you're configuring. (Which would imply there's already another customer using that domain.) If you can serve content from another customer's domain who is on the same shared host as you, that's a serious security vulnerability with the hosting platform without respect to whether or not Let's Encrypt exists.