Hacker News new | ask | show | jobs
by naraniano 3196 days ago
Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.
2 comments

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it.

Any CA that issues certificates publicly need to check CAA from the 8th of September onward.

[1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Ah, so they are three days late. That doesn't sound too serious.
On a requirement they voted for half a year ago for a standard specified 5 years ago. It's sloppy and sloppy is not a property you want in a certificate authority.
From experience working with them, sloppy is an excellent way to describe Comodo.
Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.
The ballot was in March, so they have 6 month to prepare for it, not only 3 days to implement a surprising change.
Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.
That makes no difference as to when the three days where. I never made any claims as to why it's late or them lying. I merely clarified that the three days were over a period where people don't usually work.
These 3 days don't matter when you have months of lead time.
I wonder about what else is Comodo being "not too serious" while they promise to be "super serious" about them in their marketing campaigns?
> Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs?

CAA was made up by... drumroll.... Comodo.

Yes, check the authors on the RFC: https://tools.ietf.org/html/rfc6844