Live data from Hacker News

Comodo fails to check CAA records

mail-archive.com

1–10 of 71 posts

Re: Comodo fails to check CAA records

#3
Curious to see how the CAB will handle this or if they're going to be "soft" as it's the first days of the CAA enforcement. Historically, they've been very accurate in enforcing their rules, which could mean a serious reprimand of Comodo.

If anyone is interested in testing their own CAA records, we built an online CAA validator specifically for this; https://dnsspy.io/labs/caa-validator

Re: Comodo fails to check CAA records

#5
post #3

Curious to see how the CAB will handle this or if they're going to be "soft" as it's the first days of the CAA enforcement. Historically, they've been very accurate in enforcing their rules, which could mean a serious reprimand of Comodo. If anyone is interested in testing their own CAA records, we built an online CAA validator specifically for this; https://dnsspy.io/labs/caa-validator

Between their decision to release a rebranded "more secure" version of Chrome where their changes had introduced security holes, and their decision to try and trademark "Let's Encrypt", I can't imagine they have many friends in the CAB.

On the other hand, they issue a lot of certs - if you've used Cloudflare's free SSL stuff, you've got a Comodo certificate - so they're unlikely to be shut down or anything that extreme.

Re: Comodo fails to check CAA records

#8

Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it.

Any CA that issues certificates publicly need to check CAA from the 8th of September onward.

[1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Re: Comodo fails to check CAA records

#9

Is it expected from all CAs that they obey CAA records, or is it something just made up by the community to crush the big CAs? I see an RFC from just a few years ago, and I'm not sure how these things are standardised.

Standardization goes through the CA/B forum. There was a ballot voted to make CAA checking mandatory for CAs[1], and COMODO voted yes for it. Any CA that issues certificates publicly need to check CAA from the 8th of September onward. [1] https://cabforum.org/2017/03/08/ballot-187-make-caa-checking...

Ah, so they are three days late. That doesn't sound too serious.

Re: Comodo fails to check CAA records

#10

Worth noting that the rule they broke has only been in effect for three days ( https://cabforum.org/2017/03/08/ballot-187-make-caa-checking... ). This might cause the CAB to go a bit easier on them.

They also voted "yes" to the proposal and had 6 months to implement it.
Post reply on HN