3 ms·
I was looking at the how it works[1] article but it isn't clear to me how the domain is validated. Couldn't an MITM between the LetsEcnrypt service and the exa
by hrjet 12y ago
I was looking at the how it works[1] article but it isn't clear to me how the domain is validated.
Couldn't an MITM between the LetsEcnrypt service and the example.com server request a certificate, then respond to the challenge, and then use that certificate later?
Getting a certificate from StartSSL was similar. The only difference was that there was a human involved in the loop (a mail is sent and the user has to copy paste the contents of the email), but in essence, both the services seem vulnerable.
This seems to be an unsolvable bootstrapping problem, unless some sort of physical verification is done.
What am I missing?
[1]: https://letsencrypt.org/howitworks/technology/ https://letsencrypt.org/howitworks/technology/
- vertex-four 12y agoThe protocol asserts that you have control over the domain, and over a machine that can be accessed at the domain's A record. If you can make your machine appear to be at google.com from the perspective of LetsEncrypt for the duration of the request process, you can get a cert from them. This is standard for all domain-validation-only certificate authorities, i.e. the cheapest cert you can get from any given company.