Website Security & Threat Management
CAA of the Wild: Supporting a New Standard

CAA of the Wild: Supporting a New Standard

12/7/2017 · Max Nystrom

What this post added

This post details Cloudflare's adoption and rollout of the Certification Authority Authorization (CAA) Resource Record standard. It explains the purpose of CAA records in enhancing SSL certificate issuance security by allowing domain owners to specify authorized Certificate Authorities (CAs). The post highlights Cloudflare's beta program for testing CAA support, its eventual removal of the beta flag for all users, and its integration with Universal SSL. It also delves into the complexities and potential issues with the CAA record processing algorithm, particularly concerning CNAME records and wildcard domains, demonstrating Cloudflare's proactive approach to supporting and refining new internet security standards.

Read the original post ↗