3 ms·
> The way you verify your identity to Let's Encrypt is the same as with other certificate authorities: you don't really. You place a file somewhere on your webs
by meeho 3y ago
> The way you verify your identity to Let's Encrypt is the same as with other certificate authorities: you don't really. You place a file somewhere on your website, and they access that file over plain HTTP to verify that you own the website. The one attack that signed certificates are meant to prevent is a man-in-the-middle attack. But if someone is able to perform a man-in-the-middle attack against your website, then he can intercept the certificate verification, too. In other words, Let's Encrypt certificates don't stop the one thing they're supposed to stop.
Doesn't ssl handshake require knowing the private key?
- brohee 3y agoObtaining the initial certificate is somewhat vulnerable to MitM if the attacker can divert the verification request to a server under its control. Some countries (including Iran IIRC) went as far as using BGP announces to do that (which makes it very obvious). Let's Encrypt uses Multi-Perspective Validation (https://letsencrypt.org/2020/02/19/multi-perspective-validation.html https://letsencrypt.org/2020/02/19/multi-perspective-validat...) in order to protect from most interception of the DV request.
- TYMorningCoffee 3y agoYes, but SSL is not used for plain HTTP. Also, I think you meant TLS but that is only used in HTTPS not HTTP.
- ipsi 3y agoNo, he's specifically referencing the initial setup step of Let's Encrypt, where you don't have a valid HTTPS cert so Let's Encrypt has to connect to your server over HTTP, see here: https://letsencrypt.org/docs/challenge-types/ https://letsencrypt.org/docs/challenge-types/ And yes, technically he's not wrong. Well, technically he is wrong, in that it wouldn't be a MITM attack, exactly, but if an attacker can intercept requests sent to your domain by LE and respond however they want, they can generate an LE cert for your domain, even if you're not using Let's Encrypt. That said, they can't intercept generation of the LE certificate - the HTTP request is just to prove that you've got enough control over the domain to justify issuing one. Using HTTPS wouldn't prevent that. I'm actually not sure how you would prevent that, short of removing HTTP-01 from the spec and requiring DNSSEC and so on. EDIT: I see a sibling comment pointed out that Let's Encrypt are aware of this, and are using "multi-perspective validation" to make requests from multiple regions, making this attack much harder to pull off (but never impossible, I suspect): https://letsencrypt.org/2020/02/19/multi-perspective-validation.html https://letsencrypt.org/2020/02/19/multi-perspective-validat...