Registry control undermined domain validation

Attackers obtained unauthorized TLS certificates for several Google domains and other major online services after compromising infrastructure associated with three country-code top-level domains, according to a security report published on October 7. The incidents affected the .gh, .sl and .as namespaces.

The attackers changed authoritative Domain Name System records and nameserver delegations for selected domains. That control allowed them to direct validation traffic and satisfy automated checks used by certificate authorities to confirm that an applicant controls a domain. The certificate authorities followed existing industry procedures; Google said the affected organizations' own infrastructure was not breached.

TLS certificates bind a domain name to a cryptographic public key. Browsers and other clients use the certificate and a corresponding private key to authenticate a service and establish an encrypted connection. A certificate issued to an attacker can therefore help impersonate an affected site if the attacker can also intercept or redirect traffic.

Google worked with the issuing certificate authorities to revoke certificates covering its properties and updated Chrome to block all unauthorized certificates it had identified. The company said Chrome users did not need to take action for the known certificates. It did not disclose the specific Google domains, identify the other affected organizations or state how many certificates were issued.

Site operators urged to monitor logs

Google cautioned that browser-level blocking is not a complete remedy. Its investigation may not have found every affected certificate, and protections added to Chrome do not necessarily cover people using other software. Domain operators were advised to watch public Certificate Transparency logs for unexpected issuance and publish restrictive Certification Authority Authorization records in DNS. Those records can limit which authorities may issue certificates for a domain and reduce opportunities to reuse cached validation after DNS control is restored.

Formal certificate revocation can propagate slowly, so browser vendors also maintain faster block lists for specific credentials. The known risk has been reduced now that identified certificates are blocked, but an undiscovered certificate could remain useful to an attacker.

The episode exposes a dependency in the web's trust system: automated certificate issuance assumes DNS control is legitimate. Compromise at a registry can invalidate that assumption for many organizations at once without breaching their servers. It also makes independent monitoring important. Certificate Transparency can reveal an issuance after it occurs, while restrictive DNS policy and registry security can narrow the path attackers used in these incidents.