3 ms·
If all a domain-validation SSL cert means is that the certificate issuer could reach you via admin/administrator@domain.com - that's nearly all they do, besides
by STRML 11y ago
If all a domain-validation SSL cert means is that the certificate issuer could reach you via admin/administrator@domain.com - that's nearly all they do, besides ask for some payment information - why not automate that part of the process?
That is, the certificate presented by the site should be signed in a fashion that proves that whoever signed it owns the domain.
How do we know you own the domain? Because you control the DNS. If you control the DNS, you can control the domain in so many ways, including receiving the DV email, so it seems like a proper way to verify it.
If you control DNS, you can set a TXT record and put a public key in it.
So why not have browsers actually just ensure that a certificate is signed by the public key stored in DNS? Is there a good reason not to do this?
- mikeash 11y agoMight just be because you need DNSSec for that technique to be viable (otherwise an attacker could just spoof the DNS response too) and that hasn't been widely available until recently. Offhand it sounds like a pretty good approach now.
- IgorPartola 11y agoPoint is, this is what we do now. We do this without DNSSEC. The step of receiving the email is pretty much redundant and is only there because people understand email better than creating a TXT record. DNSSEC is a terrible ide and should be abandoned for many reasons. So should this method of domain validation. You know who knows for sure that you own the domain you say you own? The registrar. That is who should issue you your cert, not some third party.
- clinta 11y agoThis is called DANE described in RFC 6698. But it requires DNSSEC. Without DNSSEC, the visitor to the site can be easily be MITM'd by spoofing DNS. It is presumably more secure when a CA verifies an email (or DNS) because the CA can control their DNS servers and be reasonably sure their DNS is not spoofed. Random clients internet clients can't without DNSSEC.