Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, they work by being able to issue a cert for the specific domain that is pointed at them.

It does not work by allowing them to issue a wildcard cert for the entire domain.

For example, `nrmitchi.com` is pointed at Netlify. Netlify can obtain a certificate for `nrmitchi.com` (and `www.nrmitchi.com`, which is also pointed at them). It does not allow Netlify to obtain a cert for `*.nrmitchi.com`, nor should it.



Technically today it does allow them to get such a certificate, but they choose not to (and Let's Encrypt has never allowed this because it's unsafe). Ballot SC45 for the Baseline Requirements this year fixed that so that from December they will not be able to get a wildcard certificate based on proving control over the parent domain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: