Skip to content
Open
Changes from 1 commit
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
34c69a0
Update 3.2.2.8
wthayer Jan 2, 2025
931a430
Update CPS requirement
wthayer Jan 3, 2025
7ab7800
Move to ca-defined method labels
wthayer Jan 3, 2025
1c745f6
Add 8657 compliance
wthayer Jan 3, 2025
eb6123c
Add 8555 and 8657 references
wthayer Jan 3, 2025
9966da5
Link section refs
wthayer Jan 3, 2025
102b4d8
Incorporate Clint's DNSSEC requirements
wthayer Jan 22, 2025
ce01855
Specify validationmethods format
wthayer Jan 22, 2025
5104234
Ben's 3.2.2.8 wording suggestions
wthayer Jan 24, 2025
194b9de
Reformat 3.2.2.8 and add subsections
wthayer Jan 26, 2025
6102730
Attempt to clarify dns-01 vs ca-dv-7 processing.
wthayer Jan 26, 2025
5b1be0a
Incorporate today's discussion
wthayer Feb 6, 2025
e43b1b7
dv to tbr in example
wthayer Feb 6, 2025
60b6607
Align CPS section requirement
wthayer Feb 7, 2025
72cf68b
Remove section link
wthayer Feb 7, 2025
772c9b3
Allow multiple accounturi formats
wthayer Feb 11, 2025
dc7546e
Add effective date for CPS + label format
wthayer Feb 11, 2025
9f609ff
Move 3.2.2.8 to 4.2.1.1
wthayer Mar 6, 2025
ea59002
Update 3.2.2.9 reference
wthayer Mar 6, 2025
15d5107
Revert DNSSEC requirements
wthayer Mar 6, 2025
797e82f
Fix heading levels
wthayer Mar 6, 2025
794c7f0
Move to 4.2.2 like SBRs
wthayer Mar 6, 2025
d3d28a3
Remove strict RFC 8555 compliance requirement.
wthayer Mar 27, 2025
bc33f4c
Add To-do for 3.2.2.8.1
wthayer Mar 27, 2025
9296059
Merge branch 'main' into SC-XX-Process-RFC-8657-CAA-Parameters
wthayer Dec 31, 2025
eeffb88
Merge in SC-085 changes
wthayer Dec 31, 2025
538a803
Merge Grace's CAA Parameters proposal
wthayer Dec 31, 2025
76f7f53
Remove duplicated MPIC language
wthayer Jan 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions docs/BR.md
Original file line number Diff line number Diff line change
Expand Up @@ -1082,6 +1082,11 @@ CAs MAY check CAA records at any other time.

When processing CAA records, CAs MUST process the issue, issuewild, and iodef property tags as specified in RFC 8659, although they are not required to act on the contents of the iodef property tag. Additional property tags MAY be supported, but MUST NOT conflict with or supersede the mandatory property tags set out in this document. CAs MUST respect the critical flag and not issue a certificate if they encounter an unrecognized property tag with this flag set.

EFFECTIVE DD-MM-YYY:
When processing CAA records, CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657. In addition:
* When the certificate request does not use the ACME protocol defined in RFC 8555, the CA MUST define the recognized format of the accounturi in their CPS.
* The CA MUST only recognize validationmethods parameters in the format "tlsbr-" + the 3.2.2.4 subsection number that defines the permitted validation method, e.g. "tlsbr-18" represents Agreed-Upon Change to Website v2.

If the CA issues a certificate after processing a CAA record, it MUST do so within the TTL of the CAA record, or 8 hours, whichever is greater.

RFC 8659 requires that CAs "MUST NOT issue a certificate unless the CA determines that either (1) the certificate request is consistent with the applicable CAA RRset or (2) an exception specified in the relevant CP or CPS applies." For issuances conforming to these Baseline Requirements, CAs MUST NOT rely on any exceptions specified in their CP or CPS unless they are one of the following:
Expand Down
Loading