Re: CAA records on a CNAME

2019-03-17 Thread Hector Martin 'marcan' via dev-security-policy
On 16/03/2019 10:25, Jan Schaumann via dev-security-policy wrote: someapp.example.com, over which I have control is a CNAME, so I can't set a CAA record there. Let's say the CNAME points to ghs.googlehosted.com. Your suggestion is to contact Google and ask them to please add a CAA record to

Re: CFCA certificate with invalid domain

2019-03-17 Thread Nick Lamb via dev-security-policy
On Fri, 15 Mar 2019 19:41:58 -0400 Jonathan Rudenberg via dev-security-policy wrote: > I've noted this on a similar bug and asked for details: > https://bugzilla.mozilla.org/show_bug.cgi?id=1524733 I can't say that this pattern gives me any confidence that the CA (CFCA) does CAA checks which