Elektrine lite

← Feed

@agowa338@chaos.social

Post #3087440

2026-02-26 17:55 UTC

@InfobloxThreatIntel@infosec.exchange I've seen people also do this for legitimate reasons. Like e.g. running fedi instances. And they've quite been pissed by the CA/Browser Forum changing the rules for TLS certificates so that you can't get ones for *.arpa domains anymore (soon at least). So I guess your problem will solve itself then?

Replies (2)

  • @agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange I was literally just thinking about the one Fedi instance running on .ARPA domain. Was one of the first things I found when I joined Fedi. Very cool. Unfortunate, but unsurprising, to see the technique adapted for harm.

    Open ##3087441

  • @nygren@hachyderm.io 2026-02-27 13:41

    @agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange Yes, the CA/B Forum rules preventing issuing new .arpa certs kick in on March 15th so by mid-year at least the DV versions of these will all be expired. The issue is at https://github.com/cabforum/servercert/issues/153 and ballot is at https://cabforum.org/2025/11/10/ballot-sc-086v3-sunset-the-inclusion-of-ip-reverse-address-domain-names/ I'm unconvinced that the reasons for doing this are legitimate more than cute/clever, and the benefits of prohibiting outweigh the impacts.

    Open ##3087443