Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Doesn't Let's Encrypt's verification require creating files with random names in http://example.com/.well-known/acme-challenge where example.com is the certificate's common name?

Are you asking whether this is an issue for the http-01 challenge?

If so, the answer is no, because if you wanted to use this to obtain a cert for some domain you don't own, the DNS reponse for that domain would have to already point to the shared hosting server you're configuring. (Which would imply there's already another customer using that domain.)

If you can serve content from another customer's domain who is on the same shared host as you, that's a serious security vulnerability with the hosting platform without respect to whether or not Let's Encrypt exists.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: