Reply to post:

Let's Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers' domains

Lysenko

With an HTTP-01 challenge, the client (cert requester) has to prove it controls HTTP (Port 80) for the domain. With TLS-SNI-01 it only had to prove it could reply from the same IP address as the domain.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon