SSL vendor practices
Hi Everyone, Not going to name names, but I have recently witnessed a client who has registered a few SSL certs to subdomains for a domain they do not own. I thought this was against the practice of registrars, can someone point me to any code of conduct on this kind of thing.
Seems very dodgy if this high level registrar is allowing this what else are they allowing, what is the point of SSL if they are going to do this. Should I report it to their internal support, or is there someone higher I can go to?
Seems very dodgy if this high level registrar is allowing this what else are they allowing, what is the point of SSL if they are going to do this. Should I report it to their internal support, or is there someone higher I can go to?
A+, C|EH, CISSP, CISM, CRISC, GSTRT, MCSA:Messaging, MCSE:Security
"Brain does not meet certification requirements, please install more certifications" Me
Currently Studying: Cyber Security masters and ISC2 CCSP.
Security blog; http://security.morganstorey.com
"Brain does not meet certification requirements, please install more certifications" Me
Currently Studying: Cyber Security masters and ISC2 CCSP.
Security blog; http://security.morganstorey.com
Comments
"Brain does not meet certification requirements, please install more certifications" Me
Currently Studying: Cyber Security masters and ISC2 CCSP.
Security blog; http://security.morganstorey.com
I would think it's generally against policy for anyone to try and get issued a cert for a domain they're not responsible for, much like trying to apply for a driver's license using a fake name.
IPSec VPN Design 44%
Mastering VMWare vSphere 5 42.8%
Having said all that - what's the point / worry ? If you do have a certificate, you need to install it on the loadbalancer / firewall / webserver. So even if someone buys a certificate of a domain (or subdomain) he doesn't own, there isn't much he can do unless he has access to the infrastructure, and installing it on another domain would cause cert errors which I am sure is as useful as self signed certs.
Or am I missing something obvious ?