LWN.net Logo

Fraudulent certificates in the wild — again

Fraudulent certificates in the wild — again

Posted Jan 5, 2013 21:17 UTC (Sat) by JanC_ (guest, #34940)
In reply to: Fraudulent certificates in the wild — again by kleptog
Parent article: Fraudulent certificates in the wild — again

The basic problem is that any CA can sign for any domain. That's the problem we should be working on. Once that is solved the rest becomes tractable.
That would require some out-of-band system to check which CA can sign for which domain. But then, how do you make sure you can retrieve that info securely?


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds