On Tuesday, 12 September 2017 10:38:56 UTC+1, Inigo Barreira  wrote:
> Futhermore, according to the logs, at the time of checking for a CAA record, 
> there was none. The lookup was succesful and hence allowed the issuance.

Given that this contradicts the facts alleged in Quirin's tests and the 
feedback from BuyPass I would strongly recommend doing further testing to 
ensure that StartCom's systems detect [and log] timeouts and other failures 
properly for CAA records. I'm sure Quirin will try to offer reasonable 
assistance in reproducing the problem.

It is definitely worth noting that with DNSSEC _enabled_ a CA ends up having 
cryptographic proof of their results - which could be recorded in case of any 
dispute. If you had such proof for the permissive CAA record we wouldn't need 
to investigate StartCom's systems or policies, we could examine the record and 
conclude that Querin made an error somewhere and permitted this issuance 
without knowing anything about StarCom or needing to take you at your word.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to