arXiv · 2411.07702
A Call to Reconsider Certification Authority Authorization (CAA)
Abstract
Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine its effectiveness in preventing certificate misissuance. Our discussion reveals pitfalls and highlights best practices when designing security protocols based on DNS.
Explore related subjects
Keep this discovery
Pouyan Fotouhi Tehrani, Raphael Hiesgen, Thomas C. Schmidt, Matthias Wählisch. 2024-11-12. A Call to Reconsider Certification Authority Authorization (CAA). https://doi.org/10.1109/msec.2025.3531232
Cite the original work for its findings. Save a collection to share your selection of sources.