SSL.com: DCV bypass and issue fake certificates for any MX hostname

Discussion in 'privacy technology' started by FanJ, Apr 19, 2025 at 9:41 AM.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
    Bug 1961406 Opened 19 hours ago Updated 3 hours ago

    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406

    Cert revoked:
    https://crt.sh/?id=17926238129&opt=ocsp

    Thanks to Erik at security.nl :
    https://www.security.nl/posting/884827/Domain Validation en OCSP
     
  2. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
    Preliminary Incident Report is published.
    See above mentioned Bugzilla thread for the Summary:
    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406
    See postings by Rebecca.

    Read there more for the details!!!

    Further down in that thread the other 10 certificates (that were mis-issued and have now been revoked) were given.
    ===

    One more quote:
     
    Last edited: Apr 22, 2025 at 6:19 PM
  3. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.