3 ms·
More interesting to me will be when one of the ACME CAs will implement RFC 8657, ACME-specific CAA parameters. Currently privilege separation on a server or a
by Tobu 5y ago
More interesting to me will be when one of the ACME CAs will implement RFC 8657, ACME-specific CAA parameters.
Currently privilege separation on a server or a TLS terminator doesn't do much for ACME privileges because an exploit anywhere on the request path can use an arbitrary account to obtain new certs.
Binding to a single ACME account in DNS (accounturi=…) would significantly reduce the attack surface, as would requiring non-http validation methods.
- Tobu 5y ago(See here for a status update, kind of) https://community.letsencrypt.org/t/rfc-8657-caa-extension-in-production/154552 https://community.letsencrypt.org/t/rfc-8657-caa-extension-i...