Skip to Content [alt-c]


In reply to Duplicate Signature Key Selection Attack in Let's Encrypt

Reader Eivind on 2015-12-04 at 07:18:

Thank you, that was a very informative explanation.

BTW, can't Mallory (e.g. NSA++) inject fake DNS responses (QUANTUMLEAP, or whatever it is called) to the ACME server to falsely "prove" it is the owner of Bob's domain, and then get certificates for his domain? Is dns txt records as authentication good enough?

(typing on cell phone, so painful aitocorrect)


Post a Reply

Your comment will be public. If you would like to contact me privately, please email me. Please keep your comment on-topic, polite, and comprehensible.

(Optional; will be published)

(Optional; will not be published)

(Optional; will be published)

  • Blank lines separate paragraphs.
  • Lines starting with ">" are indented as block quotes.
  • Lines starting with two spaces are reproduced verbatim.
  • Text surrounded by *asterisks* is italicized.
  • Text surrounded by `back ticks` is monospaced.
  • URLs are turned into links.
  • Use the Preview button to check your formatting.