|
|
|
|
|
by superuser2
3935 days ago
|
|
Any CA performing domain ownership validation would be vulnerable to the same thing. If you can fake its WHOIS requests or make it appear as if the domain making the request does in fact have the "canary" file they told you to host to prove ownership, then you can get any CA to give you a cert for any site. You have to trust something. |
|