Hacker News new | ask | show | jobs
by bifurcation 4230 days ago
Yes, we plan to apply a few mitigations of this type. Part of the idea of the "Proof of Possession of a Prior Key" challenge is so that if a web server requests a cert for a domain with an existing certificate, we can ask them to prove that they hold that certificate.

https://github.com/letsencrypt/acme-spec/blob/master/draft-b...

2 comments

Also, it seems possible that large scale DOS could be performed by applying for domains (via DNS hijack) before the owners do, causing significant administrative burden to recover from. I would suggest allowing simpler revocations within some multiple of the DNS TTL value for the domain.

I can also envision unscrupulous registrars pre-applying for LE certs for a fee, like $5.99 per month, and being very tardy and uncooperative about relinquishing control.

This is a horrible idea... I have numerous certs for my domain and collecting them all to prove to you I own them is not going to be fun.
You wouldn't be in a very good position to revoke them then, would you? For example, if we had another heartbleed.
I have access to manage them, however the private keys are either in various services or non exportable with AWS...