DNS Record for Domain CA?

51 views
Skip to first unread message

Lester Waters

unread,
Jan 22, 2017, 2:48:51 PM1/22/17
to certificate-transparency
As a further extension to the proposal, one could indicate the issuing Certificate Authority for their domain via DNS in a TXT record (akin to an SPF record). For example:

   TXT = "v=ct1 root={public-signing-key or thumbprint}"

One could go a step further and include a thumbprint of their certificate(s) for the domain:

   TXT = "v=ct1 root={public-signing-key or thumbprint}  c={certificate-thumbprint}"

This would be a simple and fast DNS check and could be much more expediant than checking the database.  If the CT1 TXT record is present, then it is observed. This raises the bar further as it potentially eliminates a window of time where a rogue certificate is used but before it is observed / witnessed as such.


Eran Messeri

unread,
Jan 23, 2017, 7:40:32 AM1/23/17
to certificate-...@googlegroups.com
How is that different from CAA records?

--
You received this message because you are subscribed to the Google Groups "certificate-transparency" group.
To unsubscribe from this group and stop receiving emails from it, send an email to certificate-transparency+unsub...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages