Hi, On 20/03/17 22:02, y-iida--- via Public wrote: > New text reads: > CAA checking is optional for certificates for which a > Certificate Transparency pre-certificate was created and > logged in at least two public logs, and for which CAA was > checked. > > This ends with ``for which CAA was checked.'' Does it mean > that CA MUST look up DNS CAA resource records, regardless of CT > logging?
I don't quite understand the question. The entire point of the ballot is to make it mandatory (i.e. MUST) in almost all circumstances for CAs to look up DNS CAA resource records. The text you quote is one of the small number of exceptions, which basically says you don't have to do it twice for CT (although you can if you like and it's easier). Gerv
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Public mailing list [email protected] https://cabforum.org/mailman/listinfo/public
