Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC9495
Discuss this RFC: Send questions or comments to the mailing listspasm@ietf.org
Other actions:Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 9495
The Certification Authority Authorization (CAA) DNS resource record(RR) provides a mechanism for domains to express the allowed set ofCertification Authorities that are authorized to issue certificatesfor the domain. RFC 8659 contains the core CAA specification, whereProperty Tags that restrict the issuance of certificates that certifydomain names are defined. This specification defines a Property Tagthat grants authorization to Certification Authorities to issuecertificates that contain the id-kp-emailProtection key purpose inthe extendedKeyUsage extension and at least one rfc822Name value orotherName value of type id-on-SmtpUTF8Mailbox that includes thedomain name in the subjectAltName extension.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.