{"id":183672,"date":"2026-10-07T22:54:13","date_gmt":"2026-10-07T20:54:13","guid":{"rendered":"https:\/\/prohoster.info\/blog\/news\/komprometacziya-registratorov-3-domennyh-zon-pozvolila-poluchit-tls-sertifikaty-k-servisam-google"},"modified":"2026-10-07T22:54:20","modified_gmt":"2026-10-07T20:54:20","slug":"compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services","title":{"rendered":"The compromise of 3 domain registrars allowed the acquisition of TLS certificates for Google services.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Google has reported an incident in which attackers managed to obtain TLS certificates for certain Google domains (such as google.as), online services, and major companies in the zones &#171;.gh&#187;, &#171;.sl&#187;, and &#171;.as&#187;. The attack was executed by compromising the registrars of national top-level domain zones \u2014 &#171;.gh&#187; (Ghana), &#171;.sl&#187; (Sierra Leone), and &#171;.as&#187; (American Samoa), allowing them to replace DNS servers for domains in these zones and redirect requests to the attackers' servers. By redirecting traffic, the attackers were able to confirm ownership of the domains and obtain TLS certificates, as after changing the data in the DNS, verification requests from certificate authorities were sent not to the real hosts but to the substituted ones and processed there.    <\/p>\n<p>Unauthorized certificate issuance was discovered as a result of analyzing Certificate Transparency logs, in which certificate authorities reflect all issued and revoked certificates. Google blocked the illegitimate certificates obtained during the attack using the CRLSets mechanism in the Chrome browser and also succeeded in revoking these certificates from the certificate authorities. It is not yet revealed for which specific domains the fraudulent certificates were issued and which companies were affected by the attack.    <\/p>\n<p>To minimize risks of similar incidents recurring, domain owners are advised to establish continuous monitoring of public CT (Certificate Transparency) logs to detect unauthorized certificate issuance. It's recommended to add CAA (Certification Authority Authorization) records in DNS, defining the list of certificate authorities authorized to issue certificates for the specified domain. Setting a CAA DNS record will not protect against certificate requests after DNS spoofing, but after regaining control over DNS, it will prevent the reissuing of certificates by attackers using cached domain ownership verification data.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=66415\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e\u0431 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0435, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0434\u043b\u044f \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u043e\u043c\u0435\u043d\u043e\u0432 Google (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, google.as), \u043e\u043d\u043b\u0430\u0439\u043d-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0432 \u0437\u043e\u043d\u0430\u0445 &#171;.gh&#187;, &#171;.sl&#187; \u0438 &#171;.as&#187;. \u0410\u0442\u0430\u043a\u0430 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044e \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 \u043d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u0445 \u0434\u043e\u043c\u0435\u043d\u043d\u044b\u0445 \u0437\u043e\u043d \u0432\u0435\u0440\u0445\u043d\u0435\u0433\u043e \u0443\u0440\u043e\u0432\u043d\u044f &#8212; &#171;.gh&#187; (\u0413\u0430\u043d\u0430), &#171;.sl&#187; (\u0421\u044c\u0435\u0440\u0440\u0430-\u041b\u0435\u043e\u043d\u0435) \u0438 &#171;.as&#187; (\u0410\u043c\u0435\u0440\u0438\u043a\u0430\u043d\u0441\u043a\u043e\u0435 \u0421\u0430\u043c\u043e\u0430), \u0447\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u043b\u043e \u0437\u0430\u043c\u0435\u043d\u0438\u0442\u044c DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0434\u043b\u044f \u0434\u043e\u043c\u0435\u043d\u043e\u0432 \u0432 \u044d\u0442\u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-183672","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e\u0431 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0435, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0434\u043b\u044f \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u043e\u043c\u0435\u043d\u043e\u0432 Google (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, google.as), \u043e\u043d\u043b\u0430\u0439\u043d-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0432 \u0437\u043e\u043d\u0430\u0445 &quot;.gh&quot;, &quot;.sl&quot; \u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Alexander Kovalev\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044f \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 3 \u0434\u043e\u043c\u0435\u043d\u043d\u044b\u0445 \u0437\u043e\u043d \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u043b\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u043a \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c Google | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e\u0431 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0435, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0434\u043b\u044f \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u043e\u043c\u0435\u043d\u043e\u0432 Google (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, google.as), \u043e\u043d\u043b\u0430\u0439\u043d-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0432 \u0437\u043e\u043d\u0430\u0445 &quot;.gh&quot;, &quot;.sl&quot; \u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T20:54:13+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T20:54:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 The compromise of registrars of 3 domain zones allowed the acquisition of TLS certificates for Google services | ProHoster","description":"Google announced an incident in which attackers were able to obtain TLS certificates for specific Google domains (for example, google.as), online services, and major companies in the zones \".gh\", \".sl\", and.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u044f \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 3 \u0434\u043e\u043c\u0435\u043d\u043d\u044b\u0445 \u0437\u043e\u043d \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u043b\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u043a \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c Google | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043e\u043e\u0431\u0449\u0438\u043b\u0430 \u043e\u0431 \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u0435, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c TLS-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0434\u043b\u044f \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u043e\u043c\u0435\u043d\u043e\u0432 Google (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, google.as), \u043e\u043d\u043b\u0430\u0439\u043d-\u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0438 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0432 \u0437\u043e\u043d\u0430\u0445 &quot;.gh&quot;, &quot;.sl&quot; \u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/compromise-of-registrars-for-three-domain-zones-enabled-tls-certificate-issuance-for-google-services","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-10-07T20:54:13+00:00","article:modified_time":"2026-10-07T20:54:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=183672"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183672\/revisions"}],"predecessor-version":[{"id":183673,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183672\/revisions\/183673"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=183672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=183672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=183672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}