Are there any known issues with CNAME flattening [aka ALIAS/ANAME] and HTTP-01 / TLS-ALPN-01?

Thanks Ryan.

As there are no standards on this, and it is "cheating the limitation in the DNS specs on the DNS provider side" as you perfectly stated, I'm worried about how the implementation details of any one provider accomplishing this might cause issues.

This is also the sort of thing I was hoping to get more insight on. It is a much better description of this 2019 thread - CAA 403 issue, with multiple CNAME configuration - #3 by luuk .

We haven't hit this yet, but could. I'm going to need to define some polices for this.

2 Likes