4 ms·
Yes, we plan to apply a few mitigations of this type. Part of the idea of the "Proof of Possession of a Prior Key" challenge is so that if a web server request
by bifurcation 12y ago
Yes, we plan to apply a few mitigations of this type. Part of the idea of the "Proof of Possession of a Prior Key" challenge is so that if a web server requests a cert for a domain with an existing certificate, we can ask them to prove that they hold that certificate.
https://github.com/letsencrypt/acme-spec/blob/master/draft-barnes-acme.md https://github.com/letsencrypt/acme-spec/blob/master/draft-b...
- iancarroll 12y agoThis is a horrible idea... I have numerous certs for my domain and collecting them all to prove to you I own them is not going to be fun.
- angry_octet 12y agoYou wouldn't be in a very good position to revoke them then, would you? For example, if we had another heartbleed.
- iancarroll 12y agoI have access to manage them, however the private keys are either in various services or non exportable with AWS...
- angry_octet 12y agoAlso, it seems possible that large scale DOS could be performed by applying for domains (via DNS hijack) before the owners do, causing significant administrative burden to recover from. I would suggest allowing simpler revocations within some multiple of the DNS TTL value for the domain. I can also envision unscrupulous registrars pre-applying for LE certs for a fee, like $5.99 per month, and being very tardy and uncooperative about relinquishing control.