Skip to content

Comment on Ssl.com: DCV bypass and issue fake certificates for any MX hostnameparent

Comments

You can see the cert was revoked here https://crt.sh/?id=17926238129

Unclear who revoked that but I think it likely was the reporter who discovered the bug. They only needed it issued & logged as evidence, and would be good practice to revoke immediately.

The certificate remained unrevoked in OCSP until after SSL.com acknowledged the issue, so I don’t think the reporter was the one who had it revoked.

It is also possible I was being served a stale/cached OCSP response.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.