LWN.net Logo

Fraudulent *.google.com certificate issued

Fraudulent *.google.com certificate issued

Posted Aug 31, 2011 16:34 UTC (Wed) by cesarb (subscriber, #6266)
In reply to: Fraudulent *.google.com certificate issued by raven667
Parent article: Fraudulent *.google.com certificate issued

Did you also whitelist all the needed DNS servers? When on untrusted networks, I usually run the bind DNS server on my laptop (querying directly the root servers) so it can validate the records using DNSSEC.


(Log in to post comments)

Fraudulent *.google.com certificate issued

Posted Aug 31, 2011 18:03 UTC (Wed) by raven667 (subscriber, #5198) [Link]

No, the only dns servers allowed through the captive portal prior to authentication are the recursive ones we maintain, these are what are suggested via DHCP. I imagine your config would break on a lot of captive portals unless they had blanket rules allowing any dns traffic.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds