Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
feld (feld@bikeshed.party)'s status on Thursday, 16-Nov-2023 02:24:56 JSTfeld @tykling Continuing this line of thought:
your original scenario had the attacker control an NS. If they can control an NS they control whether or not it serves CAA records.
Does LetsEncrypt and ZeroSSL ensure responses from *ALL* NSes are identical before proceeding?