Trusted Signing - Asked for insecure way to verify domain ownership

Richard S 0 Reputation points
2024-08-05T15:21:42.6433333+00:00

During set up of the Identity verification on Trusted Signing we are being asked for domain purchase invoices and registry records. We are unable to provide these and we challenge that these are very insecure ways to verify domain ownership and require divulging more information than is needed (i.e. Microsoft doesn't need to know what domain registrar we use or what else was purchased at the same time, or how much we paid. This is all over-reach).

The rest of Azure uses TXT DNS domain records to prove CURRENT ownership, which is a much more secure way to do this.

Security risk: If I bought a domain 11 months ago and since sold it on, I can still be verified under this approach, even if I no longer have access to the domain. With the use of TXT DNS records I could not bypass this security check, making this option much more secure.

Please allow us to use TXT DNS records to verify domain ownership and not this inconsistent and insecure method.

Azure Trusted Signing
Azure Trusted Signing
Trusted Signing is a Microsoft fully managed, end-to-end signing solution that simplifies the certificate signing process and helps partner developers more easily build and distribute applications.
73 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 32,311 Reputation points Microsoft Employee
    2024-08-06T06:32:48.65+00:00

    @Richard S Thank you for reaching out to us, As per our documentation - https://video2.skills-academy.com/en-us/azure/trusted-signing/quickstart?tabs=registerrp-portal%2Caccount-portal%2Ccertificateprofile-portal%2Cdeleteresources-portal Trusted Signing at this time can onboard only legal business entities that have verifiable tax history of three or more years by verifying the domain via txt record wont meet this requirement.

    However tagging my colleague @Meha-MSFT for more information on the above ask.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.