Issue certificates only to specific agent keys

A few months ago when the topic last came up here, I at least got the impression that one of the main things that needed to happen was a lot of testing and fleshing out all the corner cases of the specification. They need to ensure that they're dealing with ambiguous, malformed, or multiple CAA entries exactly correctly, because issuing a certificate in violation of a CAA record is a Big Deal of a problem (for good reason).

So if you wanted to contribute some time (rather than, say, money; I'm not sure which you meant) to trying to shake out all the details and building a test suite to run against the staging environment, I suspect that's the only thing that might be able to help make the process go faster. Though I suppose it's possible that a large enough monetary contribution might influence the engineers' priority list too. :slight_smile:

6 Likes