Re: Server certificate domain validation bug

2016-07-29 Thread Nick Lamb
Hi Robin, On Friday, 29 July 2016 18:54:56 UTC+1, Robin Alden wrote: > We received a report of bugs in the construction of the emails we send out > in order to confirm authorization by the domain name registrant prior to > issuing a server certificate. > > Colloquially these are known as

Re: Server certificate domain validation bug

2016-07-29 Thread Hanno Böck
Hi, I just saw this report and my initial reaction was that it seems to be a grave security risk to use HTML emails with user controlled content for email domain validation. I don't see any need for this and would strongly recommend that a policy forbidding that practice gets implemented. The

Server certificate domain validation bug

2016-07-29 Thread Robin Alden
We received a report of bugs in the construction of the emails we send out in order to confirm authorization by the domain name registrant prior to issuing a server certificate. Colloquially these are known as Domain-Control Validation Emails. The security researcher, Matthew Bryant, followed