7 ms·
> This is imperfect, as CAA record validation is not mandatory yet. But by March 2027 all the CAs a supposed to have support. Is that true? My read of Section
by aleksejs 4mo ago
> This is imperfect, as CAA record validation is not mandatory yet. But by March 2027 all the CAs a supposed to have support.
Is that true? My read of Section 1.2.1 in [1] suggests CAA checking has been mandatory since 2017‐09‐08.
[1] https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.2.7.pdf https://cabforum.org/working-groups/server/baseline-requirem...
- mcpherrinm 4mo agoCAA checking is mandatory, so you can always restrict to a given CA. To get complete control with DNSSEC, you also need the accounturi and validationmethod extensions (which you need to guarantee only your account can issue, and only with the DNS validation type). Those aren't yet mandatory, but you can restrict to a CA today which implements them, like Let's Encrypt.
- j16sdiz 4mo agoDNSSEC is the weakest link here. It is too fragile (multiple point of failure). It is high volume (=it need be cacheable). Puting authentication cert in dns sounds good in theory, but we have never get that reliability
- Hizonner 4mo ago> It is too fragile (multiple point of failure). If your DNS isn't working, you're not going to be making connections anyway. And if you can't keep DNSSEC running, you can't keep certs up to date either. DNSSEC is actually much simpler, with fewer failure points, once you set it up. > It is high volume (=it need be cacheable). It is. Unlike certificates. And the cache lifetimes are much shorter than typical certificate lifetimes.
- tptacek 4mo agoIt is self-evidently not correct that companies that can't keep DNSSEC running can't keep certs running. Entire TLDs have fallen off the Internet because DNSSEC has broken. A certificate never took Slack down for half a day. It's just obviously not true.
- Hizonner 4mo agoIt's amazing what practice and investment can do, even for a fragile system like X.509. Yet certs still break constantly. Like permanently killing people's "perpetual" Microsoft Word licenses in a story posted within hours of this one.
- mcpherrinm 4mo agoEven without DNSSEC, the CAA record approach can help, as it requires MITMing between the CA and the DNS server, which may be harder in some cases than just MITMing a target site. There’s some upcoming attempts at transport security for authoritative DNS servers which might help too: https://datatracker.ietf.org/doc/html/draft-hoffman-deleg-secure-transports https://datatracker.ietf.org/doc/html/draft-hoffman-deleg-se...
- westurner 4mo agoIs there a Transport-Secured-Only flag in a DNS spec? How to ensure that a CAA cert fingerprint is not retrieved over unsecured DNS? Re: DNS security and NTP and Decentralized DNS/PKI with web standards like W3C DID and DID micro-ledgers for record signing: "Cert Authorities Check for DNSSEC from Today" (2026-03-26) https://news.ycombinator.com/item?id=47401716 https://news.ycombinator.com/item?id=47401716
- tptacek 4mo agoThere is not.
- 8organicbits 4mo agoI have it partially right. The extensions are not yet mandatory. https://www.feistyduck.com/newsletter/issue_137_acme_caa__extensions_to_become_mandatory https://www.feistyduck.com/newsletter/issue_137_acme_caa__ex...