Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BRs: Clarify whether 3.2.2.8 can be delegated #274

Open
sleevi opened this issue May 4, 2021 · 1 comment · Fixed by #475
Open

BRs: Clarify whether 3.2.2.8 can be delegated #274

sleevi opened this issue May 4, 2021 · 1 comment · Fixed by #475
Labels
baseline-requirements Server Certificate CWG - Baseline Requirements enhancement

Comments

@sleevi
Copy link
Contributor

sleevi commented May 4, 2021

CA/B Forum Ballot 187 made CAA checking Mandatory for CAs, a revision of Ballot 125 which had CAs document their CAA policies.

CA/B Forum Ballot 204, adopted 4 months after, forbade CAs from delegating the performance of 3.2.2.4 and 3.2.2.5 (DNS and IP validation).

@CBonnell raised on the management list that this suggests that CAs are allowed to delegate part, or all, of the CAA validation to third parties, as this is located within section 3.2.2.8, which Ballot 204 does not speak to.

Ballot 187 is structured in a way to describe when a CA may choose to not check CAA (i.e. if doing as part of a precert/final cert issuance and the precert was checked and logged, if issuing from a technically constrained sub CA, or if an affiliate of the CA, notwithstanding draft ballot SC26). However, it doesn't explicitly address the delegation to a third-party (e.g. a non-technically constrained sub-CA) and how that performance is measured.

Given the critical security importance of 3.2.2.8, which was the reason and rationale for not allowing 3.2.2.4/3.2.2.5 to be delegated, it seems important to clarify whether or not 3.2.2.8 can or should be delegated to third parties.

@barrini
Copy link
Contributor

barrini commented May 29, 2024

Let´s wait for PAG outcome

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
baseline-requirements Server Certificate CWG - Baseline Requirements enhancement
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants