Certification Authority Authorization Record Extensions for Account URI and Automatic Certificate Management Environment Method Binding
RFC 8657, “Certification Authority Authorization Record Extensions for Account URI and Automatic Certificate Management Environment Method Binding”, is a Proposed Standard document published in November 2019 by H. Landau. The canonical text is published by the RFC Editor.
Abstract
The Certification Authority Authorization (CAA) DNS record allows a domain to communicate an issuance policy to Certification Authorities (CAs) but only allows a domain to define a policy with CA-level granularity. However, the CAA specification (RFC 8659) also provides facilities for an extension to admit a more granular, CA-specific policy. This specification defines two such parameters: one allowing specific accounts of a CA to be identified by URIs and one allowing specific methods of domain control validation as defined by the Automatic Certificate Management Environment (ACME) protocol to be required.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8657 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8658 RADIUS Attributes for Softwire Mechanisms Based on Address plus Port
- RFC 8655 Deterministic Networking Architecture
- RFC 8659 DNS Certification Authority Authorization Resource Record
- RFC 8654 Extended Message Support for BGP
- RFC 8660 Segment Routing with the MPLS Data Plane
- RFC 8653 On-Demand Mobility Management
- RFC 8661 Segment Routing MPLS Interworking with LDP
- RFC 8652 A YANG Data Model for the Internet Group Management Protocol and Multicast Listener Discovery