5 ms·
Even then, use of a DNS CAA record should mitigate this, right?
by mukesh610 1y ago
Even then, use of a DNS CAA record should mitigate this, right?
- jsheard 1y agoYeah - unless you're an actual SSL.com customer, in which case your CAA records would allow it. That's a much smaller blast radius at least.
- AdamJacobMuller 1y agoMaybe? I wouldn't assume that the bug doesn't bypass CAA checking. Very important question to answer.