Skip to Content [alt-c]
In reply to Duplicate Signature Key Selection Attack in Let's Encrypt
Thank you, that was a very informative explanation.
BTW, can't Mallory (e.g. NSA++) inject fake DNS responses (QUANTUMLEAP, or whatever it is called) to the ACME server to falsely "prove" it is the owner of Bob's domain, and then get certificates for his domain? Is dns txt records as authentication good enough?
(typing on cell phone, so painful aitocorrect)
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.
Your Name: (Optional; will be published)
Your Email Address: (Optional; will not be published)
Your Website: (Optional; will be published)
Post a Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.