← CABF Ballot Browser
SC-002 failed

Ballot SC002: Validating Certificates via CAA CONTACT

Server Certificate Working Group

Key dates

Voting opened
19 Jul 2018 7 years ago
Voting closed
26 Jul 2018 7 years ago
Discussion opened
11 Jul 2018 7 years ago
Discussion closed
19 Jul 2018 7 years ago

Resources

AI Summary

Generated 2026-06-23 21:24 UTC

Ballot overview

  • Ballot SC002, Validating Certificates via CAA CONTACT, proposed changes to the Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates.
  • The ballot added new validation methods using CAA contact information published in DNS or legacy TXT records.
  • It also added Appendix B: CAA Contact Tag, defining the contact property and its allowed URL schemes.

What the ballot would have changed

  • Added validation methods for domain owner email and phone contact published in DNS.
  • Added equivalent legacy validation methods using TXT records.
  • Required the CA to use the email address or phone number found in the CAA Contact property record or the DNS TXT record, depending on the method.
  • Limited the Random Value used in email validation responses to no more than 30 days from creation, unless the CPS specified a shorter period.
  • Allowed the methods to validate multiple FQDNs in some cases and noted suitability for wildcard domain names.
  • Defined the CAA contact property as a way for domain owners to publish contact information in DNS for certificate validation purposes.
  • Stated that the CAA contact property SHOULD be used instead of TXT records where feasible.

Ballot outcome

  • The voting period ended and the ballot failed.
  • Voting by CAs met the approval threshold.
  • Voting by browsers did not meet the approval threshold.
  • The ballot states that SC2 fails.

Dates

  • Discussion period: 2018-07-11 10:30am EST to 2018-07-19 11:00am EST
  • Vote for approval period: 2018-07-19 11:00am EST to 2018-07-26 11:00am EST
Model: gpt-5.4-mini Confidence: 0.99 Result: failed
Voting opened
2018-07-19
Voting closed
2018-07-26
Discussion opened
2018-07-11
Discussion closed
2018-07-19

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Proposers

Tim Hollebeek of DigiCert and endorsed by Bruce Morton of Entrust and Doug Beattie of GlobalSign.

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC002: Validating Certificates via CAA CONTACTBallot SC002: Validating Certificates via CAA CONTACTThe voting period for Ballot SC2 has ended and the ballot has failed. Here are the results.

View on cabforum.org → Last fetched 15 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action