5 ms·
The Name Constraints extension can limit the applicability of a CA cert to certain subdomains or IP addresses.
by fleminra 2y ago
The Name Constraints extension can limit the applicability of a CA cert to certain subdomains or IP addresses.
- thayne 2y agoHow well supported is that?
- 8organicbits 2y agoIt's hard to say, but I'm super interested if anyone has statistics. Netflix built https://bettertls.com/ https://bettertls.com/ to answer these sorts of questions, but somehow forgot to validate constraints set at the root: https://github.com/Netflix/bettertls/issues/19 https://github.com/Netflix/bettertls/issues/19 Anecdotally, I've seen name constraints kick in for both Firefox and Chrome on a Linux distro, but I can't comment more broadly.
- layer8 2y agoIt's required by RFC 5280 (and predecessor), so it’s fairly well supported.
- 8organicbits 2y agoDo you have any references for that? There are lots of RFCs that are weakly adopted or even ignored. When I tested Chrome they didn't support name constraints, but have since added support. I suspect other software is still lagging.
- thayne 2y agoFrom the issue for support on chrome, it sounds like RFC 5280 requires it for intermediate CAs, but is ambiguous on whether it is required for root CAs (which in this case, is where you want it). So chrome didn't support it on root CAs until recently, at least on Linux. Although, ideally, it would be possible to limit the scope of a CA when adding it to the trust store, and not have to rely on the creator of the CA setting the right parameters.