|
|
|
|
|
by 8organicbits
23 days ago
|
|
One suggestion for anyone concerned about this weakness. You can use the CAA record to pin the domain to a specific certificate authority, issuance method, and account. This is imperfect, as CAA record validation (edit: of CAA extensions) is not mandatory yet. But by March 2027 all the CAs a supposed to have support. Sprinkle some DNSSEC on the CAA record too, if you'd like. |
|
[0]: https://developers.cloudflare.com/ssl/edge-certificates/caa-...