3 ms·
Why does this happen? It seems technically solvable. If you want a cert, you have to prove you own that domain. No amount if faxing or email is going to truly p
by biturd 14y ago
Why does this happen? It seems technically solvable. If you want a cert, you have to prove you own that domain. No amount if faxing or email is going to truly prove that.
And Chrome hasn't asked me to update, am I safe or do these updates happen unbeknownst to me server side?
If people can lie, they will, and there will be security issues. In this case a wildcard got out for *.google.com! MITM all google.com email, sounds fun!
Correct me if I'm wrong, but there isn't a single google webmaster tools or analytics account out there connected to the wrong domain. Why? Because to engage those services you must own the domain and have access to it.
Google makes you put an HTML file they generate in root or add a meta tag. They then request that URL and look for the resource.
If you want an SSL cert, you should have to put a file at example.com/ssl.html
Wildcard SSL's are trickier. My previous SSL provider charged over 100.00 per cert and that was as a reseller. They wouldn't even offer wildcards in the beginning. I believe they do now but it's a significant application process.
You still could require the placement of a file but that doesn't entirely prove they should get a wild cert for the domain. It still seems better than nothing and would have stopped the issuing of this particular cert.
Not to mention, wouldn't you think every CA or intermediate has a blacklist if domains they simply don't provide certain for? Google, Facebook, twitter, LinkedIn, every major ISP, etc.
Or what about using DNS as a means of authentication. If you want an SSL cert you have to add a TXT record of ssl. TXT (value issuer provides). Again, in this case, they would have failed the ability to interact with google DNS and no matter what DNS server they asked would tell the same.
They could set up a phony DNS server, but the issuer has no reason or knowledge to follow that out of band chain. Then the only way is a rogue employee, which is something no technology is going to solve and probably will remain a risk of all business security from SSL certain to banks to brick and mortar inventory shrink.
All these methods are fully automatic and should be of little burden to the registrar to implement. It's not like they have to handle a million requests a day. A page that spits out a hash of the domain and curl's the resource could probably handle most registrars load.
- enneff 14y agoProve to whom? The people that issued this cert were effectively (albeit mistakenly) a certificate authority. They could issue whatever certs they liked.