Skip to content

Commit 1c745f6

Browse files
authored
Add 8657 compliance
- validationmethod labels must comply with section 4 of RFC 8657 - Update effective date format - Add 'this section' to CPS requirements.
1 parent 7ab7800 commit 1c745f6

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

docs/BR.md

+3-4
Original file line numberDiff line numberDiff line change
@@ -1082,10 +1082,9 @@ CAs MAY check CAA records at any other time.
10821082

10831083
When processing CAA records, CAs MUST process the issue, issuewild, and iodef property tags as specified in RFC 8659, although they are not required to act on the contents of the iodef property tag. Additional property tags MAY be supported, but MUST NOT conflict with or supersede the mandatory property tags set out in this document. CAs MUST respect the critical flag and not issue a certificate if they encounter an unrecognized property tag with this flag set.
10841084

1085-
EFFECTIVE DD-MM-YYY:
1086-
When processing CAA records, CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657. In addition:
1087-
* If the CA accepts certificate requests via any protocol other than the ACME protocol defined in RFC 8555, the CA MUST define the recognized format of the accounturi in their CPS.
1088-
* The CA MUST define each recognized validationmethods label, along with the corresponding 3.2.2.4 subsection number, in their CPS.
1085+
*Effective September 15, 2025*, when processing CAA records, CAs MUST process the accounturi and validationmethods parameters as specified in RFC 8657. In addition:
1086+
* If the CA accepts certificate requests via any protocol other than the ACME protocol defined in RFC 8555, the CA MUST define the recognized format of the accounturi in this section 3.2.2.8 of their CPS.
1087+
* The CA MUST define each recognized validationmethods label, along with the corresponding 3.2.2.4 subsection number, in this section 3.2.2.8 of their CPS. Labels MUST comply with section 4 of RFC 8657.
10891088

10901089
If the CA issues a certificate after processing a CAA record, it MUST do so within the TTL of the CAA record, or 8 hours, whichever is greater.
10911090

0 commit comments

Comments
 (0)