Comment by maxgashkov
1 hour ago
You're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.
There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').
So no, proper registrars never use webserver control as means to prove identity or ownership.
No comments yet
Contribute on Hacker News ↗