Remix.run Logo
maxgashkov 2 hours ago

Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.

sandeepkd an hour ago | parent | next [-]

On a different note, adding a file on webserver is one of the ACME methods (HTTP-01) to get a SSL/TLS certificate so it is indeed considered as possession method in real world already

maxgashkov an hour ago | parent [-]

You're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.

There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').

So no, proper registrars never use webserver control as means to prove identity or ownership.

sandeepkd an hour ago | parent | prev [-]

To clarify, my observation is around how it might have happened, not if this is the right way to do it