Changes

Jump to: navigation, search

CA/Forbidden or Problematic Practices

58 bytes added, 06:48, 26 January 2011
Wildcard DV SSL certificates
=== Wildcard DV SSL certificates ===
Some CAs issue domain-validated SSL certificates that can function as wildcard certificates, e.g., a certificate for *.example.com where the CA verifies only ownership and control of the example.com domain, and the certificate subscriber can then use the certificate with any site foo.example.com, bar.example.com, etc. This means that a subscriber could establish malicious SSL-protected web site that are deliberately named in imitation of legitimate sites, e.g., paypal.example.com, without knowledge of the CA. Concerns have been expressed that wildcard SSL certificates should not be issued except to subscribers whose actual identity has been validated with organizational validation (OV). (There are no EV [http://www.sslmatrix.com/rapidssl/buy-cheap-rapidssl-wildcard-ssl-certificate.aspx| Wildcard SSL] certificates.)
=== Email Address Prefixes for DV Certs ===
2
edits

Navigation menu