We tried to request a certificate for devnetsupport.cisco.com today and we received a “Policy forbids issuing for name” error. Is it possible to get an exception made in this case or should we advise them that they need to use another certificate authority?
This blacklist is not about domains being legitimate or illegitimate but basically about ensuring that we have consent and buy-in from the people who operate particular “high-value” domains.
In this case, Let’s Encrypt is not prepared to issue for cisco.com subdomains without contact from the people responsible for the cisco.com domain agreeing to that. If you think that you can get these people to get in touch to manifest their consent, I can tell you whom they need to get in touch with.