4 ms·
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that.
by euank 12y ago
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain they suggest within a wildcard range, that makes it almost certain I can create every subdomain.
- vladd 12y agoThis breaks for obvious cases such as mzzafr2pr.blogspot.com
- willthames 12y agoNot really, as while you can make the domain exist you can't make the TXT record appear in DNS.
- hueving 12y agoHow so? You would still be subject to clicking on the link in the standard email sent to webmaster@blogspot.com to prove you owned the root.
- euank 12y agoYou both have to prove that you own the ability to create dns (with blogspot sorta) and the actual content. The CA provider both lists the record name and value. You do have a good point though. I'm sure there are some services right now that allow decent control of a chosen subdomain's dns, but don't mean for you to be able to create ssl certs valid for all other subdomains too. Perhaps there should be a blacklist of sites like "blogspot". Perhaps there should be a way for a domain to indicate that wildcard certs cannot be automatically created for it without passing other conditions.