RFC6844 — DNS Certification Authority Authorization (CAA) Resource Record
RFC6844: DNS Certification Authority Authorization (CAA) Resource Record
⚠️ Obsoleted. This RFC has been superseded by RFC8659. Read the successor before relying on this document.
IETF Request for Comments
| Status | PROPOSED STANDARD |
| Publication status | PROPOSED STANDARD |
| Published | January 2013 |
| Stream | IETF |
| Obsoletes | — |
| Obsoleted by | RFC8659 |
| Updated by | — |
Abstract
The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain. CAA Resource Records allow a public Certification Authority to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by certificate issuers. [STANDARDS-TRACK]
Official sources
- Info page: https://www.rfc-editor.org/info/rfc6844
- Full text: https://www.rfc-editor.org/rfc/rfc6844.txt
- HTML: https://www.rfc-editor.org/rfc/rfc6844.html
Abstract and metadata are reproduced from the public RFC index; the full text is linked, not copied.