Google Chrome Blocks Certificates for Top-Level Domains .gh, .sl, and .as
Google Chrome has blocked unauthorized HTTPS certificates for the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) top-level domains. Attackers had compromised the DNS records for these countries' domains.
Google has blocked HTTPS certificates for several country code top-level domains (ccTLDs), including .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa), within its Chrome browser. This action follows the discovery that attackers had compromised the DNS records for these domains to obtain unauthorized HTTPS certificates.
The attackers gained access to a third-party domain registration system and modified the authoritative DNS records. They then leveraged their control over these DNS records to conduct domain ownership validation with certificate authorities. This allowed them to acquire certificates that could be used to redirect web traffic and establish imposter websites that passed verification checks.
Google stated that it noticed the attacks last week. The company indicated there is currently no reason to believe the certificate authorities acted improperly. Google has subsequently blocked the certificates in Chrome using Certificate Revocation List Sets (CRLSets) and is collaborating with the issuing authorities to revoke them.
The company advises domain owners to continuously monitor certificate logs for all their domains, including parked and country-specific ones. It also recommends implementing Certificate Authority Authorization (CAA) records to restrict which certificate authorities can issue certificates and how they are validated, thereby preventing attackers from exploiting cached validation results to obtain new certificates after an attack.