← CABF Ballot Browser
Ballot-214 passed

Ballot 214 – CAA Discovery CNAME Errata

Server Certificate Working Group

Key dates

Voting opened
20 Sep 2017 8 years ago
Voting closed
27 Sep 2017 8 years ago
Discussion opened
20 Sep 2017 8 years ago
Discussion closed
20 Sep 2017 8 years ago

AI Summary

Generated 2026-06-23 21:31 UTC

Ballot overview

  • Ballot 214, CAA Discovery CNAME Errata, is a Final Maintenance Guideline ballot in the Server Certificate Working Group.
  • The ballot page states that the voting period has ended and the ballot has passed.
  • Voting results shown on the page:
    • CAs: 13 yes, 3 no, 0 abstain; 81% of voting CAs voted in favor.
    • Browsers: 4 yes, 0 no, 0 abstain; 100% of voting browsers voted in favor.
  • The page states quorum was met and the approval thresholds were met for both CAs and browsers.
  • The page also states that at least one CA Member and one browser Member voted in favor, so the ballot was adopted.

What the ballot changes

  • Updates Baseline Requirements v1.4.9 Section 3.2.2.8, CAA Records.
  • Replaces the existing CAA checking language so that the CA must check for CAA records and follow the processing instructions for any records found, for each dNSName in the subjectAltName extension, as specified in RFC 6844 as amended by Errata 5065.
  • Keeps the requirement that if the CA issues, it must do so within the TTL of the CAA record, or 8 hours, whichever is greater.
  • Adds Appendix A to the Baseline Requirements for RFC6844 Errata 5065.
  • The appendix text describes the corrected CNAME/DNAME processing for CAA discovery and notes that CAs SHOULD limit accepted CNAME chain length, while CAs MUST process CNAME chains that contain 8 or fewer CNAME records.

Timing and applicability

  • Discussion begins: 2017-09-20 22:00 UTC
  • Vote for approval begins: 2017-09-20 22:00 UTC
  • Vote for approval ends: 2017-09-27 22:00 UTC
  • If the vote approves the ballot, a 30-day review period follows.
  • If no Exclusion Notices are filed, the ballot becomes effective at the end of the Review Period.
  • If Exclusion Notice(s) are filed, ballot approval is rescinded and a PAG is to be created.
  • The page does not give a single fixed effective date; effectiveness is conditional on the review period and whether exclusion notices are filed.
Model: gpt-5.4-mini Revised: 2026-06-23 21:27 UTC Confidence: 0.98 Result: passed
Voting opened
2017-09-20
Voting closed
2017-09-27
Discussion opened
2017-09-20
Discussion closed
2017-09-20
Applicability and conditions

2017-09-20 — The ballot becomes effective at the end of the review period If the ballot is approved and no Exclusion Notices are filed during the 30-day review period

2017-09-20 — Ballot approval is rescinded and a PAG is to be created If the ballot is approved and Exclusion Notice(s) are filed

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Phillip Hallam-Baker of Comodo Group Inc. and endorsed by Gervase Markham of Mozilla and Mads Egil Henriksveen of Buypass.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot 214 – CAA Discovery CNAME ErrataBallot 214 – CAA Discovery CNAME ErrataREVISED Results on Ballot 214 – CAA Discovery CNAME Errata

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action