Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 02:47:11 PM

Login with username, password and session length

663794 Posts
70589 Topics
145226 Members

Latest Member: oldwiseowls

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Digital Certificates, Encryption and Digital Signing
| | |-+  Validating that a CSR is legit
« previous next »
Pages: [1] Go Down Print
Author Topic: Validating that a CSR is legit  (Read 7537 times)
smithsa
Newbie
*
Offline Offline

Posts: 10


« on: May 14, 2008, 09:42:59 PM »

We all know that when a CA receives a CSR, they must verify that the CSR really came from the rightful owners of the domain named in the CSR. But is that really what happens in practice? Does the CA verify that THIS CSR came the owner, or A CSR came from the owner?

What I mean by this is that the CA will typically contact the Technical Contact (TC) and ask "I received a CSR for this domain, did you send it?". From my experience (or maybe I'm forgetting), there isn't any attempt to have the TC verify that what the CA is acting on is really the CSR that he sent. In other words, if a fraudster knows that a company is going to send a CSR to a certain CA, he could send one also. Depending on how careful the CA and TC are, the CA may end up signing the fraudster's request by mistake.

Should we be concerned by this? It seems that the only attacks I can imagine by doing this are kind of contrived. Still, is there any way to check that what the CA is signing is what the TC really sent?
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com