TLS-SNI via CAA

Hopefully our latest update improves the outlook for you somewhat: 2018.01.11 Update Regarding ACME TLS-SNI and Shared Hosting Infrastructure.

Right now our feeling is that “opting in” to TLS-SNI via CAA is still interesting, but is not the highest-impact mitigation we can do right now. In particular, many DNS providers still don’t allow setting of CAA records, which limits the number of people who could use this option. Also, it seems like the long-term outlook for TLS-SNI is quite poor, so this would be just one more angle to keep TLS-SNI on life support.