25 Feb
2019
25 Feb
'19
12:20 a.m.
On Feb 24, 2019, at 7:41 PM, Montgomery, Douglas (Fed) <dougm@nist.gov> wrote: In the 3rd attack noted below, do we know if the CA that issued the DV CERTS does DNSSEC validation on its DNS challenge queries?
We know that neither Comodo nor Let's Encrypt were DNSSEC validating before issuing certs. The Let’s Encrypt guys at least seemed interested in learning from their mistake. Can’t say as much of Comodo. -Bill