Handshake Papers
Handshake Papers
@HandshakePapers

CAA records or CT-log monitoring: prevention or detection for rogue issuance?

CAA records or CT-log monitoring: prevention or detection for rogue issuance?

How do you stop a certificate authority from issuing for your domain without permission? Two controls address this, and they sit on opposite sides of the event.

CAA (Certification Authority Authorization, RFC 8659) is preventive. A DNS record names which CAs may issue for your domain; compliant CAs must check it and refuse otherwise. It is cheap and effective against accidental or policy-violating issuance — but it binds only CAs that honor it, and a fully compromised or malicious CA can ignore it.

CT-log monitoring (Certificate Transparency, RFC 6962) is detective. Every publicly trusted certificate is logged; you watch those logs and get alerted when a certificate for your domain appears that you did not request. It cannot prevent issuance, but it guarantees you find out — including issuance by a CA that ignored your CAA.

— Set CAA to constrain well-behaved CAs and document intent.
— Monitor CT logs (e.g. via crt.sh feeds or a monitor service) to catch what CAA cannot stop.
— Treat them as a pair: prevention plus detection, never one alone.

Further reading: RFC 8659; RFC 6962; RFC 9162 (CT v2.0).

Bottom line: CAA prevents compliant misissuance, CT detects everything else — deploy both because neither closes the gap the other leaves.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.