Caution: This is an external email. Stop, assess and verify. Please take care when clicking links or opening attachments! When in doubt, report it using “report phishing” function. |
Hi,
We have two quick questions regarding method 3.2.2.4.7 and the ADN validation process:
Q1:
Under 3.2.2.4.7, if we have a CNAME chain: a.b.c.example.com ➔ d.e.f.example.com ➔ x.y.z.example.com
When identifying the ADN, must we follow the CNAME chain entirely to the final target (x.y.z.example.com)?
Can intermediate domains (e.g., d.e.f.example.com) or their pruned forms (e.g., f.example.com) also qualify as ADN candidates?
Q2:
Regarding the split between "identifying" and "validating" the ADN, during the "validation" phase, is CNAME resolution still permitted within the DNS lookup process, even when validating via the 3.2.2.4.22 method?
Thank you for your guidance.
Best Regards
蔡家宏 Chya-Hung Tsai
Director
Identification & Certificate Research
Tel: +886-2-2370-8886 ext. 722
Fax: +886-2-2388-6720
Email: cht...@twca.com.tw

10F., No. 85, Yanping South Road,
Taipei 100002, Taiwan(R.O.C.)
https://www.twca.com.tw
From: 'Aaron Gable' via Server Certificate WG (CA/B Forum) <server...@groups.cabforum.org>
Sent: Thursday, June 4, 2026 8:35 AM
To: server...@groups.cabforum.org
Cc: Rich Smith <rich....@digicert.com>; Chris Clements <ccle...@google.com>
--
Q1:
Under 3.2.2.4.7, if we have a CNAME chain: a.b.c.example.com ➔ d.e.f.example.com ➔ x.y.z.example.com
When identifying the ADN, must we follow the CNAME chain entirely to the final target (x.y.z.example.com)?
Can intermediate domains (e.g., d.e.f.example.com) or their pruned forms (e.g., f.example.com) also qualify as ADN candidates?
Q2:
Regarding the split between "identifying" and "validating" the ADN, during the "validation" phase, is CNAME resolution still permitted within the DNS lookup process, even when validating via the 3.2.2.4.22 method?
Hi Aaron,
Thank you for the clarification. We have no further questions on this matter.
Best regards,
ChyaHung
--
You received this message because you are subscribed to the Google Groups "Server Certificate WG (CA/B Forum)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
servercert-w...@groups.cabforum.org.
Caution: This is an external email. Stop, assess and verify. Please take care when clicking links or opening attachments! When in doubt, report it using “report phishing” function. |
Hi,
One more question.
If we adopt the method in Section 3.2.2.4.7 (without an underscore), the rule stating "no CNAME allowed after pruning" still fails to prevent a delegated party from unauthorized certificate issuance, correct?
This is because, during the "Verify ADN" stage, they can still utilize a CNAME pointing to a domain under the delegated party's control. Does this mean that this specific rule (no CNAME after pruning) is primarily applicable to cases where the label "begins with an underscore character"?
Best regards,
CyhaHung
To view this discussion visit https://groups.google.com/a/groups.cabforum.org/d/msgid/servercert-wg/8e6361fe90ee46b480b2bf25650b2be6%40twca.com.tw.
If we’re not mistaking the effective date for the Ballot is set to September the 15th but procedure in section 3.2.2.4 is to be adhered by the 15th of November. Why is this, wouldn’t it be possible to set the effective date for the Ballot to the 15th of November.
It might be worth clarifying which “Optionally” is applicable here. Is this:“Optionally (if there is a CNAME record)”, or is this “Optionally (if there is a CNAME record and the CA chooses to)”. I believe the intent is the second one.
If we adopt the method in Section 3.2.2.4.7 (without an underscore), the rule stating "no CNAME allowed after pruning" still fails to prevent a delegated party from unauthorized certificate issuance, correct?
This is because, during the "Verify ADN" stage, they can still utilize a CNAME pointing to a domain under the delegated party's control. Does this mean that this specific rule (no CNAME after pruning) is primarily applicable to cases where the label "begins with an underscore character"?