9/4/2025 · Joe Abley, Thibault Meunier, Vicky Shrestha, Bas Westerbaan
What this post added
This post details the unauthorized issuance of TLS certificates for Cloudflare's 1.1.1.1 DNS resolver by Fina CA. It explains the mechanics of TLS certificate validation for DNS resolvers, the role of Certificate Transparency (CT) in detecting such misissuances, and the investigation into potential malicious use. The post emphasizes the security implications of CA negligence and the importance of robust CA security practices.