IT.COM

domains Let’s Encrypt deploys new domain name validation

NameSilo
Watch

Lox

____Top Member
Impact
12,385
Multi-Perspective Validation Improves Domain Validation Security

At Let’s Encrypt we’re always looking for ways to improve the security and integrity of the Web PKI. We’re proud to launch multi-perspective domain validation today because we believe it’s an important step forward for the domain validation process. To our knowledge we are the first CA to deploy multi-perspective validation at scale.

Domain validation is a process that all CAs use to ensure that a certificate applicant actually controls the domain they want a certificate for. Typically the domain validation process involves asking the applicant to place a particular file or token at a controlled location for the domain, such as a particular path or a DNS entry. Then the CA will check that the applicant was able to do so. Historically it looks something like this:

2020-02-19-single-perspective-validation.png


read more (Let’s Encrypt)
 
1
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Yeah. They are now validating from various cloud-based providers. At the same time, they would not tell IPs to whitelist. My servers, for example, were no more able to renew letsencrypt SSL certs. or request new certs, as I block incoming http connections from a number of non-human endpoints, including various cloud providers as well as known scanning abusers like estibot/premiumdrops or OVH. A workaround would be to switch to dns-based authorization or switch to alternatives like free ssl from cpanel (not letsencrypt, would be sectigo instead).
 
1
•••
Yeah. They are now validating from various cloud-based providers. At the same time, they would not tell IPs to whitelist. My servers, for example, were no more able to renew letsencrypt SSL certs. or request new certs, as I block incoming http connections from a number of non-human endpoints, including various cloud providers as well as known scanning abusers like estibot/premiumdrops or OVH. A workaround would be to switch to dns-based authorization or switch to alternatives like free ssl from cpanel (not letsencrypt, would be sectigo instead).

The LE issue is - how to further prevent scammers from using free SSL.
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back