CAA Mandated by CA/Browser Forum
Moderator: Moderators
CAA Mandated by CA/Browser Forum
Since CAA is now mandated by the CA/Browser Forum, can you please add support for it to the primary DNS configuration interface?
https://blog.qualys.com/ssllabs/2017/03 ... wser-forum
https://blog.qualys.com/ssllabs/2017/03 ... wser-forum
Re: CAA Mandated by CA/Browser Forum
We have to upgrade all of the background PowerDNS infrastructure before we can add support for CAA records since the version we're currently running doesn't understand it. I don't have an ETA for this, but it's in the queue.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
Just wanted to say I'm interested in this feature as well. Thanks guys!
Also, are you aware the forums are using a staging LE cert?
Also, are you aware the forums are using a staging LE cert?
Re: CAA Mandated by CA/Browser Forum
We're not redirecting HTTP into HTTPS yet, it's just for testing.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
OK, everything should be all settled now. The redirect to HTTPS is in place and the certs are non-staging.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
Do you have any update as to when CAA records may be available?
Thanks again!
Re: CAA Mandated by CA/Browser Forum
I don't have a timeframe. I'm still working on slowly stepping through upgrades to PowerDNS to ensure nothing breaks horribly when I have to make major schema changes.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
Sorry to be annoying, but I couldn't resist the urge to bump this request again
Re: CAA Mandated by CA/Browser Forum
I'm cordially requesting any news on this topic.
Thanks again!
Thanks again!
Re: CAA Mandated by CA/Browser Forum
Still working on the upgrades to PowerDNS. When we first started using it they didn't have an API so we ended up having to do some command line output parsing to implement the DNSSEC features, which is totally not ideal (and I wouldn't have done it if there was another way) because any output formatting changes can break those kind of parsers.
I may just end up doing the best I can with looking for changes and expect some bug reports to come in that require fixing. Obviously I want to make sure that the actual serving of domain data doesn't break and any bug is limited to trying to make a change in the control center.
I may just end up doing the best I can with looking for changes and expect some bug reports to come in that require fixing. Obviously I want to make sure that the actual serving of domain data doesn't break and any bug is limited to trying to make a change in the control center.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
Do you have an update on this topic?
Thanks!
Thanks!
Re: CAA Mandated by CA/Browser Forum
I'm working on the last round of backend updates today before we progress to the next update that will add new record types.
Seth Mattinen, Roller Network LLC
Re: CAA Mandated by CA/Browser Forum
Do you have an update on this topic?
Thanks!
Thanks!
Re: CAA Mandated by CA/Browser Forum
Do you have an update on this topic?
Thanks!
Thanks!