-
Notifications
You must be signed in to change notification settings - Fork 491
Open
Labels
area/acmeACMEACMEbugmore info neededIssue requires more information for a decisionIssue requires more information for a decision
Milestone
Description
Sometimes ACME clients can misbehave and it's pretty easy to DoS step-ca in that case.
@MCWertGaming discovered an interaction between Caddy and step-ca
that causes a flood of ACME requests, possibly triggered by the CA being unable to do a DNS lookup of the requested domain. See #598 for step-ca context and logs, and see also caddyserver/caddy#4186 for details of the Caddy side of things (potential issue with Caddy's ACME client).
Note: Rate limiting in ACME needs to return a rate limit error as defined in the RFC.
Metadata
Metadata
Assignees
Labels
area/acmeACMEACMEbugmore info neededIssue requires more information for a decisionIssue requires more information for a decision