3 ms·
> For HTTP challenge, yes its true. I know very little about ACME, but surely this (not having a cert yet) is only true the very first time you get a cert, or
by nmadden 4y ago
> For HTTP challenge, yes its true.
I know very little about ACME, but surely this (not having a cert yet) is only true the very first time you get a cert, or if you let the existing cert expire?
- bruce511 4y agoAlas no. The http challenge method is http,regardless of whether you have an existing cert or not. However the protocol consists of a number of steps. Around 8 to 10 steps. For all but 1 of the steps you are the client connection, so these happen over https. So its not like the whole conversation is in the clear. The only step where the content is retrieved from the server is LE fetching a file, which is itself encrypted. So not over TLS, but the content itself is encrypted. So I'm not really sure how an MITM attack works here.
- nmadden 4y agoAs I understand it, the MITM attack is relying on the lack of authentication rather than lack of confidentiality. The attacker can go to LE and get a challenge file (AIUI), which they host on a fake version of the website. They then use DNS spoofing/cache poisoning/ARP spoofing/whatever to get the CA to hit their spoof website rather than the real one. This “proves” the attacker owns that domain and so they can then carry out the rest of the steps to get a cert. IMO its much harder to carry out this MITM against a CA compared to typical MITM attacks against end users. CAs generally speaking aren’t connecting to random wifi hotspots or using random ISPs etc. So you’d need to be in a pretty privileged network position to carry this out. And the multi-endpoint resolution approach seems like it would make it very hard indeed to pull off. That said, it seems a bit of a shame not to use the existing cert where one exists (which is presumably the case for most requests, which I’d expect are renewals).