Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I had the a similar problem, they refused to issue a certificate because the domain had a trademarked word in it. Seems strange they would be the ones to enforce trademarks, but I guess it could be considered as an anti-phishing measure or something.


This is a relic of the CA/B Forum (https://cabforum.org/) delegating review of brand/trademark checks to the CAs. We (CloudFlare) send hostnames to the CA for issuance and they check against internal lists, holding up anything for manual review that may violate another's trademark or be used for phishing (e.g., "pavpal" with a 'v' rather than a 'y'), etc.

Each CA has their procedures but most look at data sources like the Alexa Top 1000, and specific requests from high value targets like Microsoft, Google, etc. In some cases, e.g., Microsoft, the CAs must actually reach out to specific contacts at those firms before they can issue. In other cases, they manually review and release to us.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: