top | item 41049293

(no title)

jesboat | 1 year ago

require sufficient info to identify the validation method to be included in an extension in the precert?

discuss

order

agwa|1 year ago

Yeah, that would be a good idea.

Though sometimes the CA needs to know more than just the validation method to determine if a certificate should be revoked, and it's not practical to stuff it all in an extension (e.g. this recent GoDaddy issue which required examining past CAA queries: https://bugzilla.mozilla.org/show_bug.cgi?id=1904748).