← CABF Ballot Browser
SC-085v2 passed

Ballot SC-085v2: Require Validation of DNSSEC (when present) for CAA and DCV Lookups

Server Certificate Working Group

Key dates

Effective date
15 Mar 2026 3 months ago
Voting opened
11 Jun 2025 1 year ago
Voting closed
18 Jun 2025 1 year ago
IPR review ends
19 Jul 2025 11 months ago
Discussion opened
23 May 2025 1 year ago
Discussion closed
06 Jun 2025 1 year ago

AI Summary

Generated 2026-06-23 21:14 UTC

Ballot overview

  • Ballot SC-085v2 is titled Require Validation of DNSSEC (when present) for CAA and DCV Lookups.
  • The ballot proposes changes to the TLS Baseline Requirements so that CAs validate DNSSEC, when present, during CAA record lookups and DCV-related DNS lookups from the Primary Network Perspective.
  • The ballot page says the change is expected to have minimal impact on DNS resolvers and that domains using DNSSEC will benefit from improved security.
  • The ballot page states that the ballot sets an effective date of March 15, 2026 for these changes.

Voting and adoption

  • Voting results on the ballot page show 25 YES votes, 0 NO votes, and 1 ABSTAIN in the Certificate Issuers category.
  • Certificate Consumers recorded 4 YES votes, 0 NO votes, and 0 ABSTAIN.
  • The bylaws requirements were met for issuer votes, consumer votes, at least one affirmative vote in each category, and quorum.
  • The evidence includes no exclusion notices.

Normative changes in the redline

  • For domain authorization or control lookups by the Primary Network Perspective, DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed starting March 15, 2026.
  • The resolver used for those lookups MUST:
    • perform DNSSEC validation using RFC 4035 Section 5
    • support NSEC3 as defined in RFC 5155
    • support SHA-2 as defined in RFC 4509 and RFC 5702
    • properly handle the security concerns in RFC 6840 Section 4
  • CAs MUST NOT use local policy to disable DNSSEC validation on DNS queries associated with domain authorization or control validation.
  • For CAA record lookups by the Primary Network Perspective, DNSSEC validation back to the IANA DNSSEC root trust anchor MUST be performed starting March 15, 2026.
  • For CAA lookups, DNSSEC-validation errors observed by the Primary Network Perspective, such as SERVFAIL, MUST NOT be treated as permission to issue.
  • For Remote Network Perspectives used for Multi-Perspective Issuance Corroboration, DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed.
  • DNSSEC validation back to the IANA DNSSEC root trust anchor is outside the scope of self-audits performed to fulfill Section 8.7.
  • The CAA failure condition was revised so that a lookup failure may be treated as permission to issue only if the CA has confirmed the domain is Insecure as defined in RFC 4035 Section 4.3.

IPR review notice

  • The review notice states the review period ran from 2025-06-19 19:00:00 UTC to 2025-07-19 19:00:00 UTC.
  • The notice says members with Essential Claims must submit an Exclusion Notice before the end of the Review Period.
  • The supplied evidence does not show any exclusion notices being filed.
Model: gpt-5.4-mini Confidence: 0.98 Result: passed
Effective date
2026-03-15
Voting opened
2025-06-11
Voting closed
2025-06-18
IPR review ends
2025-07-19
Discussion opened
2025-05-23
Discussion closed
2025-06-06
Applicability and conditions

2026-03-15 — CAs must perform DNSSEC validation back to the IANA DNSSEC root trust anchor and must not use local policy to disable DNSSEC validation on those queries Primary Network Perspective DNS queries associated with validation of domain authorization or control

2026-03-15 — CAs must perform DNSSEC validation back to the IANA DNSSEC root trust anchor, must not use local policy to disable DNSSEC validation, and must not treat DNSSEC-validation errors such as SERVFAIL as permission to issue Primary Network Perspective DNS queries associated with CAA record lookups

2026-03-15 — DNSSEC validation back to the IANA DNSSEC root trust anchor may be performed Remote Network Perspectives used for Multi-Perspective Issuance Corroboration

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 25 yes 0 no 1 abstain
Certificate Consumers 4 yes 0 no 0 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

29 Yes
0 No
1 Abstain

97% yes · 0% no · 3% abstain

Proposers

Clint Wilson (Apple) and endorsed by Wayne Thayer (Fastly), Dimitris Zacharopoulos (HARICA), and Ryan Dickson (Chrome).

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC-085v2: Require Validation of DNSSEC (when present) for CAA and DCV LookupsBallot SC-085v2: Require Validation of DNSSEC (when present) for CAA and DCV LookupsVoting Results Certificate Issuers 25 votes in total:

View on cabforum.org → Last fetched 16 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action