Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution
This case involves Google Trust Services (GTS) and its use of Google Public DNS and Cloudflare as DNS resolvers for domain validation. Concerns were raised regarding whether GTS's reliance on these services constituted the use of a Delegated Third Party (DTP) and whether it complied with the CA/Browser Forum's Baseline Requirements. GTS clarified that it operates its own DNSSEC validator and does not consider Google Public DNS a DTP, as its usage is within the scope of its WebTrust audit. The case was ultimately resolved as invalid, with the conclusion that GTS's practices did not violate the Baseline Requirements.
- Bug created regarding GTS's DNS validation practices.
- Case closed as invalid after GTS's clarifications.
- Ltri representative — Created attachment detailing DNS validation concerns.
- Google representative — GTS explained its DNS validation process and addressed DTP concerns.
- Mozilla representative — Indicated intention to close the case as invalid.
- Mozilla representative — Confirmed closure of the case as invalid.