RFC 8657: Certification Authority Authorization (CAA) Record Extensions for Account URI and Automatic Certificate Management Environment (ACME) Method Binding
In plain English — editorial summary, not part of the RFC
The Certification Authority Authorization (CAA) DNS record allows a domain to communicate an issuance policy to Certification Authorities (CAs) but only allows a domain to define a policy with CA-level granularity. However, the CAA specification (RFC 8659) also provides facilities for an extension to admit a more granular, CA-specific policy. This specification defines two such parameters: one allowing specific accounts of a CA to be identified by URIs and one allowing specific methods of domain control validation as defined by the Automatic Certificate Management Environment (ACME) protocol to be required.
Document record
- Document ID
- RFC8657
- Published
- November 2019
- Authors
- H. Landau
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 11
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8659DNS Certification Authority Authorization (CAA) Resource RecordCurrent
November 2019
- RFC 8649Hash Of Root Key Certificate ExtensionCurrent
August 2019
- RFC 8636Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Algorithm AgilityCurrent
July 2019
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 8689SMTP Require TLS OptionCurrent
November 2019
- RFC 8692Internet X.509 Public Key Infrastructure: Additional Algorithm Identifiers for RSASSA-PSS and ECDSA Using SHAKEsCurrent
December 2019
- RFC 8693OAuth 2.0 Token ExchangeCurrent
January 2020
- RFC 8696Using Pre-Shared Key (PSK) in the Cryptographic Message Syntax (CMS)Current
December 2019
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?