3 ms·
CAA is fresh like IPv10. Done some tracking the last couple of months on the alexa top 1 million domains. In April 400(!) had CAA records. In August 800. 10% ha
by PappaPatat 9y ago
CAA is fresh like IPv10. Done some tracking the last couple of months on the alexa top 1 million domains. In April 400(!) had CAA records. In August 800. 10% have errors (the issuer-critical flag's value is set to 128, 4 6 or 9) where it should be either 0 or 1. iodef set to totally unusable web addressed, you name it.
As a matter of fact there are MANY large DNS service providers that do not even bother providing CAA options. If you want to name and shame, there is ample opportunity for the years to come. Getting it up and running is harder but more rewarding in the end.
- aaronmdjones 9y ago> 10% have errors (the issuer-critical flag's value is set to 128, 4 6 or 9) where it should be either 0 or 1. Are you certain? https://datatracker.ietf.org/doc/rfc6844/?include_text=1 https://datatracker.ietf.org/doc/rfc6844/?include_text=1 > The data fields are defined as follows: > > Flags: One octet containing the following fields: > > Bit 0, Issuer Critical Flag: If the value is set to '1', the > critical flag is asserted and the property MUST be understood > if the CAA record is to be correctly processed by a certificate > issuer. > > A Certification Authority MUST NOT issue certificates for any > Domain that contains a CAA critical property for an unknown or > unsupported property tag that for which the issuer critical > flag is set. > > Note that according to the conventions set out in [RFC1035], bit 0 > is the Most Significant Bit and bit 7 is the Least Significant > Bit. Thus, the Flags value 1 means that bit 7 is set while a value > of 128 means that bit 0 is set according to this convention. EDIT: Fixed formatting? I hope.