Prevent unauthorised website certificates for your domains
The big push, over the last few years, to move websites to use Transport Level Security (TLS) Certificates has been incredibly successful, in no small part to Let’s Encrypt. As always the arms race between attackers and defenders continues and with the increased adoption of TLS comes a number of attackers looking for less diligent Certificate Authorities who will issue a certificate for sites attackers may not actually own. Luckily for the rest of this post there’s a way to prevent this from happening, the Certificate Authority Authorization (CAA) DNS record.
Read on →