Skip to content
This repository has been archived by the owner on Jun 19, 2020. It is now read-only.

CAA information for domains in certificate #61

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

Santhanraj
Copy link
Contributor

Adds a "-CAA" flag which performs real-time CAA check as per RFC 6844 Section 4 (Errata 5065, 5097). The resulting record is printed as a message with "CAA:" tag, however the record values are accessible through a hash which can be used in monitoring systems. E.g., Monitor new certs in CT. If the cert was issued recently, and if the CAA information disallows such a issuance, it can be flagged for investigation.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant