Re: Permission to use Errata CAA Algorithm

2017-09-16 Thread Gervase Markham via dev-security-policy
On 15/09/17 20:24, j...@letsencrypt.org wrote: > We would like to ask the Mozilla and Google root programs on this list to > immediately grant at least temporary dispensation for CAs to implement the > CAA checking algorithm as described in this errata: > >

Permission to use Errata CAA Algorithm

2017-09-15 Thread josh--- via dev-security-policy
We applaud the recent addition of CAA checking requirements to the Baseline Requirements. However, there are known problems with the CAA checking algorithm specified in RFC 6844, and those problems are leading to many reports from our subscribers. The issues are described here: