: Friday, August 18, 2017 10:02 AM
To: Gervase Markham <g...@mozilla.org>; CA/Browser Forum Public Discussion List
<public@cabforum.org>
Cc: phill...@comodo.com; Kirk Hall <kirk.h...@entrustdatacard.com>
Subject: Re: [cabfpub] Two CAA questions
On Fri, Aug 18, 2017 a
On Fri, Aug 18, 2017 at 7:25 AM, Gervase Markham via Public <
public@cabforum.org> wrote:
> Is anyone able to explain why this scenario is at all common? Why would
> the authoritative nameservers for a domain refuse to answer queries, if
> the owner of the domain wanted the domain to work at all?
On 02/08/17 23:40, philliph--- via Public wrote:
>> We cannot, however, determine whether the "domain’s zone does not have
>> a DNSSEC validation chain to the ICANN root" because the domain's zone
>> authoritative name servers are refusing to answer our DNS queries.
>>
>> This scenario is
On 02/08/17 23:40, philliph--- via Public wrote:
>> We cannot, however, determine whether the "domain’s zone does not have
>> a DNSSEC validation chain to the ICANN root" because the domain's zone
>> authoritative name servers are refusing to answer our DNS queries.
>>
>> This scenario is
> On Aug 2, 2017, at 6:23 PM, Kirk Hall via Public wrote:
>
> I have two CAA questions from our technical group. I am posting here to see
> what others think. Do we need to make any changes to BR 3.2.2.8 (created
> under Ballot 187)? Thanks for any feedback.
>
>
I have two CAA questions from our technical group. I am posting here to see
what others think. Do we need to make any changes to BR 3.2.2.8 (created under
Ballot 187)? Thanks for any feedback.
QUESTION 1
Subject: CAA ballot and handling of REFUSED status response from authoritative
name