Skip to content
This repository was archived by the owner on Jun 19, 2020. It is now read-only.

Conversation

Santhanraj
Copy link
Contributor

Adds a "-CAA" flag which performs real-time CAA check as per RFC 6844 Section 4 (Errata 5065, 5097). The resulting record is printed as a message with "CAA:" tag, however the record values are accessible through a hash which can be used in monitoring systems. E.g., Monitor new certs in CT. If the cert was issued recently, and if the CAA information disallows such a issuance, it can be flagged for investigation.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant