Someone asked this at Let's encrypt forum. https://community.letsencrypt.org/t/support-for-https-records-in-alias-mode/250456
Baseline requirement 3.2.2.4 is silent about how CA parse DNS record to get IP address of a domain, as they are written before this become a thing. I'd say thats a hint, not an authoritative source, but It'd better write explicit rule about this -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/22216384-9094-4dd9-aded-746e6b2acb7fn%40mozilla.org.
