|
|
|
|
|
by tptacek
2106 days ago
|
|
You know this, but for the benefit of the thread: to say "tls-sni-01 is safe unless there are bulk hosting sites that break it" is to say that tls-sni-01 is unsafe. The "crazy" sites you're referring to included AWS and Heroku. This all happened 2 years ago, so it's a bit odd to see it litigated today. |
|
https://jhalderm.com/pub/papers/letsencrypt-ccs19.pdf
in case anyone is more interested (there are also references there for further details). Twice, methods that seemed plausible for proving control over domain names turned out to make assumptions that were potentially violated by shared hosting environments.
Jacques, I'm really sorry for the hassle that these changes caused you.