4 ms·
Technically it's possible to specify an IP address in a X.509 certificate. With OpenSSL you'd do something like that when issuing new certificate: subjectAltNa
by StrLght 2y ago
Technically it's possible to specify an IP address in a X.509 certificate. With OpenSSL you'd do something like that when issuing new certificate:
subjectAltName=IP:192.168.1.1
And that's actually exactly what Google's 8.8.8.8 and Cloudflare's 1.1.1.1 use in their certificates.
Also both issuers use certificate transparency [0], so BGP hijack shouldn't affect this — sure, your system might try to connect to hijacked IP, but TLS connection will fail due to invalid certificate (assuming certificate trust chain wasn't compromised and there are no malicious CAs installed on your system).
[0]: https://crt.sh/?q=1.1.1.1 https://crt.sh/?q=1.1.1.1
- notpushkin 2y ago> sure, your system might try to connect to hijacked IP, but TLS connection will fail due to invalid certificate I think the parent is asking if malicious actor can issue a certificate in case of BGP hijack. I think they could, but then it would be visible in the CT log.
- commandersaki 2y agoNah StrLght set me straight. I really didn't know how an IP address was embedded in a certificate, and I was viewing the output of the certificate from the lens of openssl s_client -connect 1.1.1.1:443 which obscures the fact that there's more than CN=cloudflare-dns.com. I think it'd be pretty hard to get a certificate for 1.1.1.1 after a BGP hijack, unless you had some control over a CA. I don't think LetsEncrypt issues certificates for IPs.