|
|
|
|
|
by cypherpunks01
3738 days ago
|
|
That is real confusing, wouldn't that imply one party is outright lying? Blog claims: In the last step of the validation process is where you can modify the email address and replace it with any regular email address StartSSL claims: The email address used to verify the domain name is listed in the WHOIS records.. |
|
Personally, I find it hard to believe that an audited CA has a system where the web frontend can make a decision as to what would be an allowed verification email address. I'm leaning towards believing their story, and would assume they have a backend system which is responsible for checking that input (and which happened to be out of sync with the options offered by the frontend). That's a reasonable explanation for the complete lack of validation in their frontend code.
Then again, some CAs have had a terrible track record, so I guess we'll never know for sure now that they fixed the issue (whatever the issue actually was).