Website cloning

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: www.bridgehousefarm.com, which is currently being cloned by www.bridgehouse-farm.co.uk. Please can the security publishing certificates be revoked as www.bridgehouse-farm.co.uk is trying to pass off as www.bridgehouse-farm.com by trying to establish fake supplier contracts

I ran this command:

It produced this output:

My web server is (include version):

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

Unfortunately I do not have the domain details requested, but would be grateful for any help that you could provide

I suggest you follow the process on the Nominet (the registry for the .uk TLD) complaints page for domain names used in connection with criminal activity. Complaints - Nominet

Upon discovering criminal activity within a building do you...

A. Report the criminal activity to the manufacturer of the building's locks and petition for removal of the locks.

B. Report the criminal activity to the appropriate law enforcement authorities and petition for cessation of the criminal activity.

I disagree kinda with comparing SSL certificates with a "lock". Its more like a business license, like a grocery store license, alcohol sales license or resturant license.

And thus, it becomes more resonable to petition for its removal. However, since Lets encrypt is a "business license" anyone can get (SHALL-ISSUE), it becomes like described in "The CA's role in fighting phishing and malware".

Think like a CCW (gun license) with shall-issue - but more business related. So while you are right that Lets encrypt wont revoke the "shall-issue business license" from the malicious page, its kinda wrong to compare it to a lock.

Well, I agree it's not really a lock, but I also don't think it's like a business license. It's more like the company that provided the house address number sign for the building, so that people could know whether they were at the address they thought they were. But it doesn't really have anything to do with what goes on in the building.

To the best of my knowledge, a CA in no way, shape, or form ever issues a license of any kind to any entity to permit any activity of that entity as a CA in no way, shape, or form possesses the sovereignty to govern the activities of any entity aside from itself via the service it provides based upon associated agreements. Therefore, petitioning a CA to cease providing its service to any entity in no way resembles enforceable denial of that entity's ability to continue performing the activities upon which the petition is based. Such a petition is, to me, little different from a petition upon a mobile phone service provider to cease providing its service to a criminal organization in hopes of halting said criminal organization's criminal activities. It is, to me, an ineffective and subversive approach to DIY law enforcement that walks a very thin line, much like having the power shut off to a neighbor's home because their electric fence is (possibly rightly) perceived as a threat to neighborhood children and pets. In my experience, denial of service rarely prevents crime; it merely shifts how crime is committed.