|
|
|
|
|
by regecks
2991 days ago
|
|
I mean, it's kind of overstated to call it rogue. A new feature of Github hosting, sure. It's a pretty common practice to do it automatically in hosting and CDNs. cPanel does it, Cloudflare does it (by themselves adding up to 10-20+% of all certificates currently trusted), a immeasurable number of SaaS-es and blogging/ecommerce platforms do it. I saw one user freak out when FastMail started doing it too for domains pointed to their static hosting. From a Web PKI perspective I feel it's fine. DV is DV after all. I do always create CAA records for my owns domains though, even if it's just: issue ";"
issuewild ";"
|
|
For CAA I would love to, but my registrar still doesn't allow me to create these kind of records :/