The CA/Browser Forum, serving as a platform for collaborative decision-making that considers the interests of browser vendors and certificate authorities, has approved new requirements for organizations issuing certificates for HTTPS. The new requirements declare 11 methods of domain ownership verification, for which a certificate is issued, to be obsolete. Support for these outdated methods will be phased out by March 2028. The reasons for discontinuing support include a focus on automatically performed and cryptographically verifiable verification methods.
The methods declared obsolete include those related to the use of information from the WHOIS service, confirming contact details via email, phone calls, faxes, SMS, or paper letters, as well as verification based on ownership checks of the IP address assigned to the domain in DNS. It is anticipated that discontinuing support for these verification methods will eliminate loopholes that could potentially allow attackers to gain control of domains they do not own. a certificate for the domain, which they do not control. For instance, a year ago, the possibility of obtaining TLS certificates for other people's domains in the '.mobi' zone was demonstrated by taking over the outdated WHOIS service of the registrar for that domain zone.
The list of domain ownership verification methods declared obsolete:
- Sending email, fax, SMS, or paper letters to the contact details listed for the domain in the WHOIS database or in the DNS SOA record.
- Sending email, fax, SMS, or paper letters to the contact details listed for the domain. an IP address.
- Sending a verification code to common email addresses such as admin@, administrator@, webmaster@, hostmaster@, and postmaster@.
- Sending a verification code to the email specified in the domain's CAA record in DNS.
- Sending a verification code to the email specified in the domain's TXT record in DNS.
- Verifying by phone call to the number specified as the contact for the domain.
- Verifying by phone call to the number specified in the domain's TXT record in DNS.
- Verifying by phone call to the number specified in the domain's CAA record in DNS.
- Verifying by phone call to the number specified as the contact for the IP address to which the domain is attached.
- Checks based on the verification of the IP address registered for the domain in DNS.
- Checks based on reverse IP resolution.
Source: opennet.ru
