Skip to content

Policy module allows honkeypot certificates without SAN to be successfully issued #1

@gnugnug

Description

@gnugnug

I'm unsure if this is an issue or a discussion item, but since the discussions feature is disabled for this repository, I'm going to post it here.

The policy file allows certificates without a Subject Alternative name extension but with an arbitrary commonName in the subject to be successfully issued. The documentation explains "This prevents malicious use while still allowing users to create certificates for themselves", however to me this looks like a needlessly dangerous configuration.

  1. Why should users be able to request certificates from a honeypot? Those certificates serve no purpose and just trigger false positive alerts.
  2. If the attacker is able to modify the altSecurityIdentities attribute of an account he can create an explicit mapping between the issued certificate and that account.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions