Private Diffie/Helman Tokens
Private Diffie/Helman Tokens
Posted Dec 6, 2024 13:10 UTC (Fri) by epa (subscriber, #39769)In reply to: Private Diffie/Helman Tokens by pitb0ss
Parent article: Let's Encrypt sets date for ending OCSP support
It does seem a bit circular. If my browser connects to foo.com then whoever is at the other end does control the foo.com domain in some sense (at least from my view of the network). So if the only thing proven by the certificate is "they control the domain", that's redundant. In practice Let's Encrypt requires that they controlled the domain at some point in the past, and so you can be reasonably sure the same person still controls it today. Indeed, you could argue for a *minimum* age of certificates, so that if an attacker took control of a domain and managed to get certificates, enough time would have passed for somebody (hopefully) to notice the attack.
