Re: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-13 Thread Quirin Scheitle via dev-security-policy
Hi, just wanted to update that Certum has also issued on this domain: https://crt.sh/?id=209378608 I have opened a support ticket, which has led to revocation but not a qualified statement as to what happened yet. Kind regards Quirin smime.p7s Description: S/MIME cryptographic signature

RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-13 Thread Inigo Barreira via dev-security-policy
:30 To: mozilla-dev-security-pol...@lists.mozilla.org Subject: Re: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone Hi all, Thank you for the replies. I am glad that there is agreement these certificates should not have been issued. I am confident that the test behaved correctly, the last edit

Re: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Quirin Scheitle via dev-security-policy
Hi all, Thank you for the replies. I am glad that there is agreement these certificates should not have been issued. I am confident that the test behaved correctly, the last edit on the zone file was on Aug 31 17:24, and it reads: crossbear.org. 0 CAA 0 issue ";" So even

RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Inigo Barreira via dev-security-policy
il.com>; mozilla-dev-security-pol...@lists.mozilla.org Subject: RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone Ok, let me investigate this further, maybe I didn´t catch it rightly. For the record, the certificate was revoked Best regards Iñigo Barreira CEO StartCom CA Limited -Original Me

RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Inigo Barreira via dev-security-policy
] On Behalf Of Nick Lamb via dev-security-policy Sent: martes, 12 de septiembre de 2017 12:26 To: mozilla-dev-security-pol...@lists.mozilla.org Subject: Re: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone On Tuesday, 12 September 2017 10:38:56 UTC+1, Inigo Barreira wrote: > Futherm

Re: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Nick Lamb via dev-security-policy
On Tuesday, 12 September 2017 10:38:56 UTC+1, Inigo Barreira wrote: > Futhermore, according to the logs, at the time of checking for a CAA record, > there was none. The lookup was succesful and hence allowed the issuance. Given that this contradicts the facts alleged in Quirin's tests and the

RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Mads Egil Henriksveen via dev-security-policy
...@lists.mozilla.org Subject: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone Hi, inspired by the ballot paragraph [1], I set up a domain that is fully DNSSEC signed [2], but does not reply to CAA queries (timeout). I could obtain certificates for this domain from Buypass and Startcom [3]. Other CAs

RE: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Inigo Barreira via dev-security-policy
Of Quirin Scheitle via dev-security-policy Sent: martes, 12 de septiembre de 2017 0:24 To: mozilla-dev-security-pol...@lists.mozilla.org Subject: (Mis)-Issuance on CAA Timeout in DNSSEC signed zone Hi, inspired by the ballot paragraph [1], I set up a domain that is fully DNSSEC signed [2], but does

(Mis)-Issuance on CAA Timeout in DNSSEC signed zone

2017-09-12 Thread Quirin Scheitle via dev-security-policy
Hi, inspired by the ballot paragraph [1], I set up a domain that is fully DNSSEC signed [2], but does not reply to CAA queries (timeout). I could obtain certificates for this domain from Buypass and Startcom [3]. Other CAs (RapidSSL, GeoTrust, LetsEncrypt) have refused to issue, and GoDaddy