Data protection

SSL certificate of a subdomain with a wrong host name

Risk Level

Hazardous (3)

Platform(s)
  • N/A

Compliance Frameworks

Description

The certificate for {Subdomain.Name} belongs to a different hostname. Certificates can authenticate only specific hostnames, stated either in the Common Name (CN) or as an Subject Alternative Name (SAN). Certificates can not guarantee ownership of a subdomain which is not listed in one of those. This means a user could not distinguish access to the correct website and a fake one and opens users of this website to the risk of an MITM attack
  • Recommended Mitigation

    Access the domain through a modern browser to see if the user is alerted on the certificate's status. Review the certificate and either add the subdomain as a SAN or create a new certificate for this subdomain.