Re: CAA record checking issue

2019-05-12 Thread Matt Palmer via dev-security-policy
On Sat, May 11, 2019 at 08:37:53AM -0700, Han Yuwei via dev-security-policy wrote: > This raised a question: > How can CA prove they have done CAA checks or not at the time of issue? They can't, just as they can't prove they have or haven't done domain-control validation. It's up to audits,

Trusted Recursive Resolver Policy in India

2019-05-12 Thread Nemo via dev-security-policy
Hi, I've been running a public DNSCrypt resolver[0] for the last 2 years, and would like to start a DoH resolver as well. I went through the DoH-Resolver-Policy page[1] and have setup a Draft Policy for my resolver that is based on it[2]. India specifically, has a lot of Internet Blocks