@techreport{wicinski-lamps-caa-00, number = {draft-wicinski-lamps-caa-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-wicinski-lamps-caa/00/}, author = {Tim Wicinski}, title = {{Alternative DNS Certification Authority Authorization (CAA) Resource Record}}, pagetotal = 3, year = 2019, month = mar, day = 24, abstract = {{[}RFC6844{]} defines the Certification Authority Authorization (CAA) DNS Resource Record type to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name. With large domains covering multiple web properties, defining all possible certificate authorities for the domain has security implications. It would be beneficial to define a CAA for individual host names. This will allow CAA records that can be managed with fine grain control. This document provides an alternative CAA record using a \_caa prefix label that will take precedent on a per Fully Qualified Domain Name (FQDN), if it exists. It will override any CAA record at the zone apex. This will not change current CAA record behavior, but will be an additional option.}, }