logo

Update: CAs Still Accepting E-mail as Proof of Domain Ownership

ID: c8d90950-ceb2-57bd-9730-46dcfd8bddd0

STIX ID: report--c8d90950-ceb2-57bd-9730-46dcfd8bddd0

Feed Name: Security Ledger

Threat Score
60/100

Date Published: 2015-03-27

Date Updated: 2026-05-05

Author: Paul Roberts

...
...

Carnegie Mellon CERT warns that many certificate authorities still issue domain-validated SSL/TLS certificates based only on control of certain email addresses (such as admin@, hostmaster@), which could allow attackers who register or hijack those addresses to obtain valid certificates and spoof HTTPS traffic; impacted CAs include COMODO, Entrust, GeoTrust, GlobalSign, and GoDaddy, and CERT recommends restricting creation of commonly accepted role addresses though a comprehensive fix requires CA policy changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.