Earlier quoted context omitted.
Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...
Ah, so they are three days late. That doesn't sound too serious.
Comodo fails to check CAA records
11–20 of 71 posts
Re: Comodo fails to check CAA records
#12maybe time to revoke Comodo's CA authority. Similar to what has happened before with Symantec (?).
Re: Comodo fails to check CAA records
#13Worth noting that the rule they broke has only been in effect for three days ( https://cabforum.org/2017/03/08/ballot-187-make-caa-checking... ). This might cause the CAB to go a bit easier on them.
Re: Comodo fails to check CAA records
#14Earlier quoted context omitted.
Ah, so they are three days late. That doesn't sound too serious.
Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
Re: Comodo fails to check CAA records
#15Earlier quoted context omitted.
Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.
Re: Comodo fails to check CAA records
#16Curious to see how the CAB will handle this or if they're going to be "soft" as it's the first days of the CAA enforcement. Historically, they've been very accurate in enforcing their rules, which could mean a serious reprimand of Comodo. If anyone is interested in testing their own CAA records, we built an online CAA validator specifically for this; https://dnsspy.io/labs/caa-validator
Re: Comodo fails to check CAA records
#17Earlier quoted context omitted.
Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.
Except they claimed to support it a long time before this. It’s not that they were late, it’s that they lied.
Re: Comodo fails to check CAA records
#18Earlier quoted context omitted.
Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.
Re: Comodo fails to check CAA records
#19Earlier quoted context omitted.
Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...
Ah, so they are three days late. That doesn't sound too serious.
Re: Comodo fails to check CAA records
#20Earlier quoted context omitted.
Three days is quite a long time to be late, so I'd hope someone over there is getting a reprimand, but yeah, it's also not a disaster. They're response and time to remedy this will be more telling I think.
Three days over a weekend, though. Context matters. Even if it's the most critical incident, you can't force employees to work outside of business hours.