3 ms·
I'm not assuming anything, and I disagree because I think it's a different problem, not the same one. Also, did you read my last sentence?
by voidz 11y ago
I'm not assuming anything, and I disagree because I think it's a different problem, not the same one. Also, did you read my last sentence?
- Guvante 11y agoYour phrasing is hard to follow. I was assuming you meant that all information necessary to validate the certificate is attached to the DNS record which is crazy as the primary reason for SSL certificates that are centrally signed is when you don't get the right DNS record for some reason (roughly speaking). If you are instead saying that you should avoid having a URL in the certificate itself, validate it as normal and then use the DNS record to match the certificate to the URL I guess that could work. However you still have the above problem where anyone who has a valid certificate at all can impersonate any website by injecting a DNS record.