Comment on Ssl.com: DCV bypass and issue fake certificates for any MX hostnameparentComments−mukesh6101yEven then, use of a DNS CAA record should mitigate this, right?−AdamJacobMuller1yMaybe?I wouldn't assume that the bug doesn't bypass CAA checking.Very important question to answer.−jsheard1yYeah - unless you're an actual SSL.com customer, in which case your CAA records would allow it. That's a much smaller blast radius at least.
Comments
Even then, use of a DNS CAA record should mitigate this, right?
Maybe?
I wouldn't assume that the bug doesn't bypass CAA checking.
Very important question to answer.
Yeah - unless you're an actual SSL.com customer, in which case your CAA records would allow it. That's a much smaller blast radius at least.