4 ms·
Use a CAA policy in your DNS to lock down the CAs that can issue for your domain, and then monitor for issued certificates with the certificate transparency log
by jamieweb 8y ago
Use a CAA policy in your DNS to lock down the CAs that can issue for your domain, and then monitor for issued certificates with the certificate transparency logs.
In modern browsers, certificates are not trusted if they're not CT-logged, so it's impossible for a fraudulent one to exist without you knowing about it (unless it was issued before these requirements were put in place in ~April 2018, but once all of those have expired, it'll be a pretty solid system).
- bmn__ 8y agoThat still does not help against the GP's problem. The most practical – yet totally ridiculous – solution in 2019 is still: for each end user, for each browser, to delete all pre-trusted CAs, and reenable them one-by-one trust-on-first-use. In a few days to weeks, the user ends up with around six active CAs that are actually in use, instead of dozens inactive ones that are just a backdoor waiting to happen.