← CABF Ballot Browser
SC-100 passed

Ballot SC100: DNSSEC Clarification and Consolidation

Server Certificate Working Group

Key dates

Voting opened
30 Jul 2026 1 week ago
Voting closed
06 Aug 2026 3 days ago
IPR review ends
05 Sep 2026 3 weeks from now
Discussion opened
30 Jun 2026 1 month ago
Discussion closed
30 Jul 2026 1 week ago

Resources

Affected document sections
Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates § 3.2.2.8.1 DNSSEC Validation of CAA Records (reference update) Updates the reference for DNSSEC validation of CAA record processing requirements to point to Section 4.2.2.2. Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates § 4.2.2.2 DNSSEC Validation Requirements (new consolidated section) Consolidates DNSSEC validation requirements into Section 4.2.2.2, including resolver requirements, applicability/scope, email partial exception, prohibition on disabling DNSSEC validation, error handling, remote perspective allowance, and exclusions. Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates § 4.2.2.1.1 CAA Multi-Perspective Issuance Corroboration (added DNSSEC validation sentence) Adds a requirement that DNSSEC validation MUST be performed in accordance with Section 4.2.2.2 on all DNS queries associated with CAA record lookups performed by the Primary Network Perspective. Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates § Effective Date and Additionally Relevant Compliance Date(s) table (DNSSEC-related entries) Replaces prior DNSSEC validation back to the IANA DNSSEC root trust anchor entries with consolidated entries under Section 4.2.2.2.

AI Summary

Generated 2026-08-09 04:00 UTC

Ballot overview

  • Ballot SC100 is titled DNSSEC Clarification and Consolidation and was proposed to address lack of clarity in DNSSEC validation requirements, including Remote Network Perspectives, and to consolidate scattered requirements.
  • The ballot moves DNSSEC validation requirements to a new Section 4.2.2.2, reorganizes structure to reduce repetition, and clarifies that DNSSEC validation MAY be performed on Remote Network Perspectives but is REQUIRED only on the Primary Network Perspective.
  • The ballot page states the intent is clarity only and that there is no intention to modify the existing requirements, and it also states this ballot does not currently have an effective date.

What the ballot changes (per provided diff text)

  • Updates the Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates by:
    • Changing DNSSEC validation language for Primary Network Perspective DNS queries associated with domain authorization/control and CAA record lookups to be consolidated under Section 4.2.2.2.
    • Replacing prior references to DNSSEC validation back to the IANA DNSSEC root trust anchor with consolidated requirements under Section 4.2.2.2.
    • Adding a new consolidated section 4.2.2.2 DNSSEC Validation Requirements, including:
      • 4.2.2.2.1 DNS Resolver Requirements (resolver must perform DNSSEC validation and support NSEC3 and SHA-2 and properly handle RFC 6840 security concerns).
      • 4.2.2.2.2 Applicability and Scope (DNSSEC validation MUST be performed by the Primary Network Perspective for DNS queries associated with validation of domain authorization/control and CAA record lookups).
      • 4.2.2.2.3 Email Domain Validation Methods - Partial Exception (for specified email-based methods, DNSSEC validation MUST be performed on CNAME/CAA/TXT queries used to obtain the Authorization Domain Name; for other queries for these methods, DNSSEC validation SHOULD be performed).
      • 4.2.2.2.4 Prohibition on Disabling DNSSEC Validation (for all other domain validation methods and for all CAA record lookups, CAs MUST NOT use local policy to disable DNSSEC validation on relevant DNS queries).
      • 4.2.2.2.5 DNSSEC Validation Errors (except as allowed by the partial exception, DNSSEC-validation errors observed by the Primary Network Perspective MUST NOT be treated as permission to issue).
      • 4.2.2.2.6 Remote Network Perspectives (DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed on DNS queries associated with validation of domain authorization/control and for CAA record lookups performed by Remote Network Perspectives as part of Multi-Perspective Issuance Corroboration).
      • 4.2.2.2.7 Exclusions (full set of DNS lookup information related to DNSSEC validation is outside the scope of self-audits in Section 8.7 and logging requirements in Section 5.4.1).

Review period and IPR exclusion mechanism (as stated on the ballot page)

  • The ballot page includes an IPR review period notice with a 30-day review period for one Final Maintenance Guidelines, and it states that members with Essential Claim(s) to exclude must forward a written Notice to Exclude Essential Claims before the end of the Review Period.
Model: gpt-5.4-nano Confidence: 0.74 Result: passed
Voting opened
2026-07-30
Voting closed
2026-08-06
IPR review ends
2026-09-05
Discussion opened
2026-06-30
Discussion closed
2026-07-30

AI-generated from the CABF ballot page. The official CABF article remains the authoritative source.

Vote result

Certificate Issuers 22 yes 0 no 0 abstain
Certificate Consumers 3 yes 0 no 0 abstain

CABF ballot approval depends on both voting classes; CA votes alone are not decisive.

25 Yes
0 No
0 Abstain

100% yes · 0% no

Proposers

Rich Smith (DigiCert) and endorsed by Trev Ponds-White (Amazon) and Scott Rea (eMudhra)

Excerpt

SearchHome » All CA/Browser Forum Posts » Ballot SC100: DNSSEC Clarification and ConsolidationBallot SC100: DNSSEC Clarification and ConsolidationVoting Results Certificate Issuers 22 votes in total:

View on cabforum.org → Last fetched 2 hours ago

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action