I recall that subdomains are their own record inside a DNS, which would imply that anyone can claim that their server is a non-existent subdomain of the real domain
I recall that subdomains are their own record inside a DNS, which would imply that anyone can claim that their server is a non-existent subdomain of the real domain
And when you are requesting a certificate for foobar.bank.com, your certificate request must come from an authorized email address at bank.com. That is also where your issued certificate would be sent. So, in order to get a certificate from a third party issuer, you have to:
Could a malicious actor compromise that mailbox in a way that allows them to request a certificate and then receive it? It’s not impossible, but it would be a huge effort with a small payout. Honestly, if you’ve got access to that mailbox, you don’t want to give yourself away by making false certreqs through it. You want to just exfiltrate as much data from it as you can. There’s certainly something way more valuable in there.
That isn’t true in general. In fact, it can’t be.
It might be policy for most cases from the well-known certificate authorities, but it’s not part of the protocol or anything like that.
If it were, then it would be impossible to set up your mailserver to begin with because you could never get a certificate for mail.bank.com
You don’t need a https cert for a Mail server, fyi
Really? They don’t use TLS at all? That sounds hilariously insecure