DNS Challenge vs HTTP

@Nummer378
I certainly don't want them issuing wildcards for *.example.com.

Limiting them for *.www.example.com might be handy - but doing that is more limited in its benefit.

I assume the CAA we're talking about doesn't apply to *.example.com - since the scope of the CNAME point for _acme-challenge.www.example.com already does that.

If I'm wrong about that, and still need the CAA to prevent wild-cards for *.example.com then this additional discussion becomes a lot more relevant.

1 Like