5 ms·
It’s amazing to me that there a multiple entities which can sign valid TLS certain for the same domain. Seems like a serious design flaw, especially with some o
by dev_dull 8y ago
It’s amazing to me that there a multiple entities which can sign valid TLS certain for the same domain. Seems like a serious design flaw, especially with some of those trust authorities being overseas
- jaas 8y agoYou can limit that by deploying CAA records for your domain in DNS. All trusted CAs are required to respect those records.
- pornel 8y agoThis is being fixed: • You can use CAA DNS records to choose which CAs can create certs for your domain. • You can watch Certificate Transparency logs to catch CAs that didn't obey. AFAIK both are becoming mandatory for CAs. It doesn't technically stop violations, but ensures they get caught and shut down if they fail to obey the rules (like StartCom and Symantec).
- kardos 8y ago> You can watch Certificate Transparency logs to catch CAs that didn't obey. Isn't there a timing issue there? Eg, if I get a cert from Comodo and change my CAA record to specify Let's Encrypt immediately afterwards, anyone checking if issuer doesn't match CAA can get a false positive
- homero 8y agoIt's only for issuers to check not clients
- icebraining 8y ago> if I get a cert from Comodo and change my CAA record to specify Let's Encrypt immediately afterwards Why would you do that?
- kardos 8y agoTo cause grief for a CA you don't much like? I'm taking issue with the idea of checking CAA records against CT logs after the fact as a means of verifying CA compliance with CAA.
- rocqua 8y agoThe idea isn't for third parties to check CT logs against CAA records. Instead, the idea is for the domain owner to check CT logs to detect CAs issuing certs that shouldn't be there. This is orthogonal to CAA records. You can check CT logs without having a CAA records, and CT logs can also be used to detect misbehavior from a CA you authorized in your CAA records. At the same time, CAA records are preventative, whilst CT logs only allow detection after the fact.
- CydeWeys 8y agoThere are people who store historical DNS records for forensic and validation purposes. And any CA worth its salt that does DV will be doing the same for any domain they're issuing certs for, at a minimum. Point is, people will be able to figure out that you're lying if you attempt to claim that the cert was issued incorrectly.
- kardos 8y agoAh, quite interesting, thanks for that. On one hand, sounds good that the obvious loophole is not wide open, on the other, it smells a bit like self regulation. I guess the next frontier is getting one of these historical DNS records made readily available alongside the CT logs.
- Spivak 8y agoWill browsers actually refuse a 'valid' cert if my DNS record indicates a different CA than the one presented?
- pmh 8y agoNo, the check is done when the CA issues the cert. This allows you to change your CAA record without making your cert invalid (see also https://tools.ietf.org/html/rfc6844#page-2 https://tools.ietf.org/html/rfc6844#page-2)
- SmellyGeekBoy 8y agoDamn those untrustworthy "overseas" people, the only trustworthy people happen to be born in the same place I was! (Wherever that is)