<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Certificate Issuance on Nalar</title>
    <link>https://nalar.dev/tags/certificate-issuance/</link>
    <description>Recent content in Certificate Issuance on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 15 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/certificate-issuance/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CAA Records Constrain Public Certificate Issuance at the DNS Boundary</title>
      <link>https://nalar.dev/caa-records-constrain-public-certificate-issuance-at-the-dns-boundary/</link>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/caa-records-constrain-public-certificate-issuance-at-the-dns-boundary/</guid>
      <description>&lt;h1 id=&#34;caa-records-constrain-public-certificate-issuance-at-the-dns-boundary&#34;&gt;CAA Records Constrain Public Certificate Issuance at the DNS Boundary&lt;/h1&gt;&#xA;&lt;p&gt;A public certificate can pass every browser check after issuance even if the domain operator never intended to use the certificate authority that created it. The Web PKI has several controls for detecting or responding to bad issuance, but DNS Certification Authority Authorization (CAA) acts earlier: it gives a domain holder a way to state which issuers are permitted to create certificates for a name.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
