ObsoletedPROPOSED STANDARDIETF stream

RFC 6844: DNS Certification Authority Authorization (CAA) Resource Record

This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 8659.

Current version: RFC 8659DNS Certification Authority Authorization (CAA) Resource Record

In plain English — editorial summary, not part of the RFC

The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain. CAA Resource Records allow a public Certification Authority to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by certificate issuers. [STANDARDS-TRACK]

Document record

Document ID
RFC6844
Published
January 2013
Authors
P. Hallam-Baker; R. Stradling
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
18
Also known as
Obsoleted by:
RFC 8659

Topics

Referenced by

One later RFC formally updates or obsoletes part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/6844-dns-certification-authority-authorization-caa-resource-record