Skip to content

Bought a dropped domain. Previous owner's SSL cert still valid. Concern?

Domain Names by mediaaustin 15 replies 860 views
#11
lucgone said:
I contact the old host directly

German lawyer here, not your lawyer, but: do they actually have to revoke on request from a third party? The certificate was issued to their former customer. You are not the customer. I would expect them to say "data protection, we cannot discuss this account."

Has anyone actually succeeded with this approach?

3 #12
DragonGone said:
Do they actually have to revoke

No, they do not have to. But they do. I have done this with Time4VPS twice, with OVH once, with Gandi once. I send email from the new WHOIS address, I include the invoice showing I own the domain, I ask politely. All four times, revoked within 48 hours.

Politesse, messieurs. It helps.

Vive la résistance... électrique
#13

Following.

Also: if you're worried about mail specifically, remember that MTA-STS and DANE exist but nobody uses them. The real risk for mail is not the old cert, it's if the previous owner had the domain on a blocklist. Check Talos, Spamhaus, Barracuda. The cert won't get your mail rejected. Your IP reputation and domain reputation will.

#14
nerdbann said:
The cert won't get your mail rejected

True for SMTP TLS, but STARTTLS downgrade is still a thing in the wild. If someone can present the old cert and intercept the connection, they can strip TLS and now you're in plaintext. It's a narrow attack window but it's real.

I will try lucgone's approach and email Time4VPS directly. Will report back.

SPF, DKIM, DMARC — holy trinity ✉️
#15

Has anyone checked if Let's Encrypt's new short-lived certs (6 days) change this problem at all? The window gets smaller but the revocation story is the same, no?

#16
hadesjones said:
Let's Encrypt's new short-lived certs

They are not fully deployed yet. And the revocation infrastructure is the same. Shorter lifetime helps only if the old owner does not reissue, which they cannot do without DNS control anyway.

The real fix is ACME CAA or DNSSEC with TLSA. Neither is happening at scale.

oops: 0000 [#1] SMP

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft