Update: CAs Still Accepting E-mail as Proof of Domain Ownership
ID: c8d90950-ceb2-57bd-9730-46dcfd8bddd0
STIX ID: report--c8d90950-ceb2-57bd-9730-46dcfd8bddd0
Feed Name: Security Ledger
Carnegie Mellon CERT warns that many certificate authorities still issue domain-validated SSL/TLS certificates based only on control of certain email addresses (such as admin@, hostmaster@), which could allow attackers who register or hijack those addresses to obtain valid certificates and spoof HTTPS traffic; impacted CAs include COMODO, Entrust, GeoTrust, GlobalSign, and GoDaddy, and CERT recommends restricting creation of commonly accepted role addresses though a comprehensive fix requires CA policy changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
