Feisty Duck
Read post

ACME CAA Extensions to Become Mandatory

The CA/Browser Forum has voted (Ballot SC-098v2) to make ACME CAA extensions mandatory for all Certificate Authorities starting March 2027. ACME CAA extensions, defined in RFC 8657, allow domain owners to lock certificate issuance to a specific ACME account and restrict validation to DNS-based methods only. When combined with DNSSEC (already mandatory for domain validation since March 2026), this closes the remaining security gaps in Web PKI by ensuring all domain validation is cryptographically secure. CAs like Let's Encrypt and Google Trust Services already support the feature, and Chrome's Root Program Policy has required ACME CAA support since February 2026. The change enables high-assurance certificate issuance for high-profile websites that face serious threats.

May 28•5m read time•From feistyduck.com
Post cover image
Table of contents
Cryptography & Security NewsletterConvergence of DNSSEC and Web PKIWeaknesses at the Root of Web PKICertification Authority AuthorizationWhat Does This Do?Can We Use ACME CAA Extensions Now?Post-Quantum CryptographyCryptographyPrivacyPKISecurity
82 Impressions
Feisty Duck's image
Feisty Duck

Piccalilli's resource offers insights, tutorials, and resources for frontend developers and web desi...

4 Followers

•

12 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard