-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Domain or IP #17
Comments
How is a CAA check performed for an IP address? |
@bwesterb In the BRs, it looks like CAA checking only applies to fully-qualified domain names, and thus there is no CAA check for IPs. |
The BR document states: So it seems validation of only domain name entries on the SAN is required when validated CAA records. Not sure if CAA records for IP addresses are a thing. There is an expired draft in LAMPS working group at IETF for this line of work but it seems to be abandoned. |
Ah, I was on a stale page so @gcimaszewski comment just got visible. With that context, I believe this issue is about supporting IP address control validation on the API, IIUC. The first comment on this issue references the CAA check description, hence the confusion. The HTTP validation method in the draft can be generalized for both domain and IP address in that case. |
draft-mpic/draft-westerbaan-secdispatch-mpic.md
Line 110 in 42ee5bf
The draft currently uses the label
domain
to refer to the domain being validated. ACME and the BRs also support certs for IP addresses. Open MPIC currently refers to this asdomain_or_ip_target
.Do we want to change the language to allow this identifier to be an IP address or a domain? How should IP address targets be handled in the future?
The text was updated successfully, but these errors were encountered: