Comment by benburkert

Comment by benburkert 3 days ago

1 reply

Sorry, not trying to obfuscate anything, hopefully this clarifies: users trust us to hold their ACME account key and we only ask for DNS records prefixed with `_acme-challenge.` to be CNAME delegated.

With this we could issue or revoke a new certificate, but we couldn't impersonate them because we don't control the rest of their DNS.

dogleash 3 days ago

> we couldn't impersonate them because we don't control the rest of their DNS.

If that were true, nobody would need signed certificates in the first place.