Glossary
Certificates
CAA record
A DNS record naming which certificate authorities may issue for a domain. CAs are required to check it at issuance time; it constrains issuance, and does nothing about certificates already issued.
Defined in RFC 8659.
Where this appears
The lessons that use this term, and what each is for.
Domain Security FundamentalsThe records worth knowing, field by fieldRead a zone’s SOA, NS, A, CNAME, MX, TXT and CAA records and say what each asserts.Domain Security FundamentalsCAA: constraining who may issueWrite a CAA policy for a domain and say exactly which issuance attempts it stops.DNS Security PractitionerReading a CAA setSay exactly which authorities may issue for a name, given a set of records.DNS Security PractitionerCAA against your own ACME clientWrite a CAA set that constrains issuance without blocking the client that renews your certificates.Domain Trust ArchitectureWhere each control sitsMap every control you have learned onto the surface it defends.Domain Trust ArchitectureThe dependency graphDraw what depends on what, and identify the controls that cannot be deployed yet.Domain Trust ArchitectureWhat to do with no budgetList the controls that cost nothing but attention, and deploy them in an afternoon.Domain Trust ArchitectureA method you can run by handAssess any estate against every surface using public data and a fixed sequence.Domain Security PractitionerPosture, domain by domainProduce the assessment table for a mixed estate and rank every finding.