I disagree. The requirements do not specify that.  All that is required is the 
name of the applicant was verified under 3.2.2.1 and that the register specify 
the domain contact is the applicant. If Google, Inc. is specified as the domain 
contact, no address matching is required.

 

From: [email protected] [mailto:[email protected]] 
Sent: Tuesday, January 2, 2018 4:34 PM
To: Jeremy Rowley <[email protected]>; CA/Browser Forum Public 
Discussion List <[email protected]>
Cc: Ryan Sleevi <[email protected]>; Adriano Santoni 
<[email protected]>
Subject: Re: [cabfpub] Verification of Domain Contact and Domain Authorization 
Document

 

 





On Dec 22, 2017, at 12:09 PM, Jeremy Rowley via Public <[email protected] 
<mailto:[email protected]> > wrote:

 

The attack vector is easier than that. 

1.      I use very stringent processes to verify that Google, Inc. is a legit 
company in Utah.
2.      I verify that Jeremy did indeed incorporate Google, Inc. 
3.      I call Jeremy at the phone listed for Google, Inc., the Utah corporation
4.      The domain information shows Google, Inc. as owning  
<http://google.com/> google.com
5.      Certificate issues.

 

Obviously this would be caught in every CA’s high risk checks, but the point 
remains valid. Regardless of the expertise and thoroughness of the org check, 
the specs lack any time between the verified org and the actual domain because 
orgs are not unique on a global basis.

 

 

For item 4, you have to verify that “the Applicant is the Domain Contact”.  
Obviously it’s insufficient to just compare names—you must verify every element 
of the WHOIS contact matches the Applicant, that’s typically name, postal 
address, phone number, and e-mail.

 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Public mailing list
[email protected]
https://cabforum.org/mailman/listinfo/public

Reply via email to