(no title)
mmalone | 5 years ago
Obviously this is all addressable in theory, but now you’d need some kinda policy system baked in pretty much everywhere.
mmalone | 5 years ago
Obviously this is all addressable in theory, but now you’d need some kinda policy system baked in pretty much everywhere.
im3w1l|5 years ago
Your website hands me a cert. I have never seen it before so I make sure CA says it's legit. From then on I keep using that same cert to connect to you, and CA no longer matters.
jlgaddis|5 years ago
corty|5 years ago
jlgaddis|5 years ago
The CAA record is useful only at the time a certificate is issued (signed) by a CA.
A client has no way to know what the CAA record was at the time the certificate was issued -- a browser cannot ("at acceptance-time") use the current value of the CAA record to determine whether a certificate was properly issued or not.