Comment on Ssl.com: DCV bypass and issue fake certificates for any MX hostnameparentComments−bawolff1yIssuing a Google certificate is a good way to get your whole CA killed.Surely what happened here is a good way to get your CA killed? The linked bug seems pretty bad.−tptacek1yLess clear on that. Bugs happen. I'm not an expert on browser root policies.−thayne1yFrom what I understand one of the factors is how often things like this happen, and how well they handle it when it does.−agwa1yHistorically, singular domain validation bugs have not killed CAs.
Comments
Surely what happened here is a good way to get your CA killed? The linked bug seems pretty bad.
Less clear on that. Bugs happen. I'm not an expert on browser root policies.
From what I understand one of the factors is how often things like this happen, and how well they handle it when it does.
Historically, singular domain validation bugs have not killed CAs.