Hi,

On 20/03/17 22:02, y-iida--- via Public wrote:
> New text reads:
>    CAA checking is optional for certificates for which a
>    Certificate Transparency pre-certificate was created and
>    logged in at least two public logs, and for which CAA was
>    checked.
> 
> This ends with ``for which CAA was checked.''  Does it mean
> that CA MUST look up DNS CAA resource records, regardless of CT
> logging?

I don't quite understand the question. The entire point of the ballot is
to make it mandatory (i.e. MUST) in almost all circumstances for CAs to
look up DNS CAA resource records. The text you quote is one of the small
number of exceptions, which basically says you don't have to do it twice
for CT (although you can if you like and it's easier).

Gerv

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Public mailing list
[email protected]
https://cabforum.org/mailman/listinfo/public

Reply via email to