Skip to content

SC-100: DNSSEC Clarification and Consolidation#667

Open
richardwsmith wants to merge 7 commits into
cabforum:mainfrom
richardwsmith:richardwsmith/SC100--DNSSEC-Clarification-and-Consolidation
Open

SC-100: DNSSEC Clarification and Consolidation#667
richardwsmith wants to merge 7 commits into
cabforum:mainfrom
richardwsmith:richardwsmith/SC100--DNSSEC-Clarification-and-Consolidation

Conversation

@richardwsmith

Copy link
Copy Markdown

Moves DNSSEC validation requirements from section 3.2.2.4 and 3.2.2.8 and consolidates them into a new section 3.2.2.10

… and consolidates them into a new section 3.2.2.10
@richardwsmith
richardwsmith requested a review from a team as a code owner May 12, 2026 16:00
Comment thread docs/BR.md Outdated
Comment thread docs/BR.md Outdated
Comment thread docs/BR.md Outdated
Comment thread docs/BR.md Outdated

@richardwsmith richardwsmith left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This line is clunky and needs some wordsmithing

Comment thread docs/BR.md Outdated
Comment thread docs/BR.md Outdated

##### 3.2.2.10.6 Remote Network Perspectives

DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed on all DNS queries associated with the validation of domain authorization or control and for CAA record lookups performed by Remote Network Perspectives as part of Multi-Perspective Issuance Corroboration.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fix

@richardwsmith richardwsmith left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR has been updated to align with section changes brought about by the incorporation of SC-098 in BR v2.2.8

richardwsmith and others added 2 commits June 26, 2026 14:13
…m DNSSEC validation requirement phrasing. Section 4.2.2.2.1 makes it clear that DNSSEC validation must be carried out in conformance with RFC 4035.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants