4 ms·
That is mostly true, unless it's malicious Certificate Authority which may, on behalf of a governments request, ignore the CAA record on purpose to generate a c
by tomputer 9y ago
That is mostly true, unless it's malicious Certificate Authority which may, on behalf of a governments request, ignore the CAA record on purpose to generate a certificate.
This is where a TLSA record would help to prevent malicious certificates. At least, if the client (browser) validates TLSA records.