3 ms·
This spec may only be usable by provider issuing certificates they manage on behalf of their customers. It's possible the protocol is unusable on a shared IP ad
by DanielDent 9y ago
This spec may only be usable by provider issuing certificates they manage on behalf of their customers. It's possible the protocol is unusable on a shared IP address for customer-managed certificates.
Even today, there are many hosting companies where you can go ahead and setup an account for "gmail.com" - and they will happily direct messages from their customers intended for "gmail.com". And there are hosting control panels where their "solution" to this problem is to have a hardcoded list of high value targets for which end customers cannot create accounts.
But the general issue is that providers need to be mindful of what changes they make to their routing tables. Not all inputs to the system are trustworthy.