4 ms·
Ownership verification is already done via DNS by existing CAs. If an attacker has full control over your DNS, he can already change the DNS records and trick a
by Wilya 12y ago
Ownership verification is already done via DNS by existing CAs. If an attacker has full control over your DNS, he can already change the DNS records and trick a CA into delivering him a genuine certificate.
This isn't really a MITM attack.
- slasaus 12y ago"If an attacker has full control over your DNS" Shouldn't this be "over the CAs DNS resolver"? /edit well I guess if the attacker has control over your dns server, ofcours, but another vector is to spoof as the CAs resolver when the CA does a lookup for your domain.
- pfg 12y agoControl of any name server used by the CA to resolve your hostname would be enough. That could be either the CAs DNS, any resolver in between (e.g. something like Google's Public DNS, which hopefully no real CA is using) or the authoritative name server of the domain. That is, unless you use DNSSEC.
- mappu 12y agoWhat existing CA's offer this? The ones i've used (godaddy, startssl, namecheap/ssls.com rapidssl/positivessl) all wanted email verification iirc. EDIT: of course that's equivalent to verifying the MX. Never mind!
- makomk 12y agoEmail verification is worse - not only can it be attacked by modifying DNS, even a passive eavesdropper can generally get enough information to verify successfully.
- Wilya 12y agoGandi offers three validation methods: * DNS: you need to add a specific record to your DNS zone * File: you need to add a specific file to the root of a HTTP server listening on the domain name * Email: they send an email to admin@ on the domain All three are pretty much ways to check that you are the person in control of the associated DNS.