nanog mailing list archives

Re: A Deep Dive on the Recent Widespread DNS Hijacking


From: Bill Woodcock <woody () pch net>
Date: Sun, 24 Feb 2019 21:20:59 -0800



On Feb 24, 2019, at 7:41 PM, Montgomery, Douglas (Fed) <dougm () nist gov> wrote:
In the 3rd attack noted below, do we know if the CA that issued the DV CERTS does DNSSEC validation on its DNS 
challenge queries?

We know that neither Comodo nor Let's Encrypt were DNSSEC validating before issuing certs.  The Let’s Encrypt guys at 
least seemed interested in learning from their mistake.  Can’t say as much of Comodo.

                                -Bill

Attachment: signature.asc
Description: Message signed with OpenPGP


Current thread: