People in Internet security circles are sounding the alarm over the issuance of three TLS certificates for 1.1.1.1, a widely used DNS service from content delivery network Cloudflare and the Asia Pacific Network Information Centre (APNIC) Internet registry.
The certificates, issued in May, can be used to decrypt domain lookup queries encrypted through DNS over HTTPS, a protocol that provides end-to-end encryption when end-user devices seek the IP address of a particular domain they want to access. Some security experts are also concerned that the certificates may underpin other sensitive services, such as WARP, a VPN offered by Cloudflare. The certificates remained valid at the time this post went live on Ars.
Key failures
Although the certificates were issued four months ago, their existence came to public notice only on Wednesday in a post to an online discussion forum. They were issued by Fina RDC 2020, a certificate authority that’s subordinate to the root certificate holder Fina Root CA. The Fina Root CA, in turn, is trusted by the Microsoft Root Certificate Program, which governs which certificates are trusted by the Windows operating system. Microsoft Edge accounts for approximately 5 percent of the browsers actively used on the Internet.
Microsoft said in a statement that it has “engaged the certificate authority to request immediate action. We’re also taking steps to block the affected certificates through our disallowed list to help keep customers protected.” The statement didn't say how it failed to identify the improperly issued certificate for such a long period of time.
Representatives from Google and Mozilla said in emails that their Chrome and Firefox browsers have never trusted the certificates, and there was no need for users to take any action. It wasn’t immediately known if a similar certificate program from Apple trusts the certificate. It was also not immediately known which organization or person requested and obtained the credentials. Representatives from Fina, Microsoft, and Apple didn’t immediately provide answers to emails seeking details.