Re: DRAFT November 2017 CA Communication

2017-10-26 Thread Kathleen Wilson via dev-security-policy
On Wednesday, October 25, 2017 at 2:05:33 PM UTC-7, Andrew Ayer wrote: > Hi Kathleen, > > I suggest being explicit about which CAA errata Mozilla allows. > > For CNAME, it's erratum 5065. > > For DNAME, it's erratum 5097. > > Link to errata:

RE: DRAFT November 2017 CA Communication

2017-10-26 Thread Tim Hollebeek via dev-security-policy
I don't like erratum 5097. It just deletes the mention of DNAME, which can easily be misinterpreted as not permitting DNAME following for CAA (or even worse, allows DNAME to be handled however you want). Erratum 5097 also has not been approved by IETF (and shouldn't be, for this reason). The