Re: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt

Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com> Thu, 13 July 2023 15:01 UTC

Return-Path: <Paul.vanBrouwershaven@entrust.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E2096C17EE09 for <acme@ietfa.amsl.com>; Thu, 13 Jul 2023 08:01:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.094
X-Spam-Level:
X-Spam-Status: No, score=-2.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Dj52BLiHfAY1 for <acme@ietfa.amsl.com>; Thu, 13 Jul 2023 08:01:50 -0700 (PDT)
Received: from mx07-0015a003.pphosted.com (mx07-0015a003.pphosted.com [185.132.183.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 70ECAC17EE2F for <acme@ietf.org>; Thu, 13 Jul 2023 08:01:50 -0700 (PDT)
Received: from pps.filterd (m0242864.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.17.1.22/8.17.1.22) with ESMTP id 36D7rVC6014574; Thu, 13 Jul 2023 10:01:47 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h= from:to:subject:date:message-id:references:in-reply-to :content-type:mime-version; s=mail1; bh=aWnnRy7uWAptwAOPK/A4oi83 Mkl+/fb+cnL41hipRnM=; b=OfqE2JJTa0pvxgoP0TsJpuEF/Zig2sFcKSWzzJcd +6KxNbrW4yv+sp/ZmTnHPWtJ97yF9iBe7vsn/WGXsLargzdDhHpkzG1O0ki9ieFq 1spt23wKl45HgL3QbX4QhtjMdHfnC7jxRYjreN7EteXMvL5qsy3eYgHcdmd4c581 +4tlnGD9NLvIjBtE7Jkqn//FW6hZIlnVgXS+fw7Cwu9LnZt1qh/Nzi6ctx4MlV3f viKWJHi2pEvkkKp/1ECmHBUgH5a16/CTw7HDJbp8ZKVzH8JC5AdGCxaHx4OmyIki jnvUMYC5lmzxUpJrYvRowPVZobMCFUqgjV1sNsizTBE7Mw==
Received: from nam12-bn8-obe.outbound.protection.outlook.com (mail-bn8nam12lp2177.outbound.protection.outlook.com [104.47.55.177]) by mx08-0015a003.pphosted.com (PPS) with ESMTPS id 3rrtmhjmqu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 13 Jul 2023 10:01:46 -0500 (CDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=k3fG5Uxrh1ppLkRjVbQNbNNab6F7O01FVkoIbb/iVwX8OGEuoZn0j2l1dYgWYI8352y6JaTKBZuBhA/tmpsR8tSydG6dXvg52/X5k6/unXLIgK+tSKYdojMD16/VanrcEzgY/6Z/k+fRXeJ6z7qqHVboFwtP3Q03VntomYWkvCkunNBzz/4XCqsu7FYpDoiKYsHy4vKleVvJEOWw1PsWn6LWfuZYZloT2eb2b4B/PeIO3mu8elpq0FyCIFzahNN/kcRKNQ+t9oFg03HnfmpF2MCtMln0eTgbcKsUeNOnszg/IVmSSBI52SaiOBZMH5mVY+F7euc801ZJkXfb+3Bw0w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=aWnnRy7uWAptwAOPK/A4oi83Mkl+/fb+cnL41hipRnM=; b=XkDAMTqZkCMgvoawlHDzNUYk+Tf/1G8kg6eMk74iHMzB6sopsK103ZUNtlS0/T8kc/blBDLtR9xBSvBY7fGuy4Z6Oxx7B7XFmGfzTzCEbAYNL88vnITU84l9DvsvTt9qUbSp2y0XjD6rYGRSQDgPMVCOYLOBsbSVOXQg82i9HyMdii3Wf7F2TOwPZVumUG9cujlKbMhDlmZsFqtTzsS/nMfh9zEp1JCTXpLb7aMxPJ/0iloVeBZnM11OtOz6+e6b/02LFHXBrxHm1g14QVOGI5i5gDVGP5q8Um78g1XOi+aTCaqIUVBEYkNmKU+jL+prwDUOTFbpYsuYesYY7JQfzA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from LV2PR11MB5975.namprd11.prod.outlook.com (2603:10b6:408:17d::6) by DM4PR11MB5972.namprd11.prod.outlook.com (2603:10b6:8:5f::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6588.20; Thu, 13 Jul 2023 15:01:43 +0000
Received: from LV2PR11MB5975.namprd11.prod.outlook.com ([fe80::eb7a:e7ee:ec73:f1b6]) by LV2PR11MB5975.namprd11.prod.outlook.com ([fe80::eb7a:e7ee:ec73:f1b6%7]) with mapi id 15.20.6588.022; Thu, 13 Jul 2023 15:01:43 +0000
From: Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com>
To: Tim Hollebeek <tim.hollebeek=40digicert.com@dmarc.ietf.org>, Seo Suchan <tjtncks@gmail.com>, Mike Ounsworth <Mike.Ounsworth@entrust.com>, "acme@ietf.org" <acme@ietf.org>
Thread-Topic: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt
Thread-Index: AQHZsBerC3uY6kYm2E+UdbTaxF5c/6+s00KAgAnMbACAAAPDAIAAqzbZgAAPo4CAABMkwoAAVQyAgAAM1Qs=
Date: Thu, 13 Jul 2023 15:01:43 +0000
Message-ID: <LV2PR11MB59757E27436AC1622562E31AF837A@LV2PR11MB5975.namprd11.prod.outlook.com>
References: <168865435873.61106.2850041921157081937@ietfa.amsl.com> <CH0PR11MB5739FDB26BF675925C449AA69F2CA@CH0PR11MB5739.namprd11.prod.outlook.com> <SN7PR14MB6492304F09384DB611AF389C8336A@SN7PR14MB6492.namprd14.prod.outlook.com> <SN7PR14MB6492DCF6E68B8C489E5E76BE8336A@SN7PR14MB6492.namprd14.prod.outlook.com> <LV2PR11MB5975CCBAEB1E8BA525CA033CF837A@LV2PR11MB5975.namprd11.prod.outlook.com> <b171161b-bb4a-c99c-27ea-6c81d5a6e418@gmail.com> <LV2PR11MB5975CEFD65D81A6851FE80FEF837A@LV2PR11MB5975.namprd11.prod.outlook.com> <SN7PR14MB6492B0CF201254DAD6B951CE8337A@SN7PR14MB6492.namprd14.prod.outlook.com>
In-Reply-To: <SN7PR14MB6492B0CF201254DAD6B951CE8337A@SN7PR14MB6492.namprd14.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LV2PR11MB5975:EE_|DM4PR11MB5972:EE_
x-ms-office365-filtering-correlation-id: f7f49fec-7cfa-49d5-61ef-08db83b211eb
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: DLMaV/Az6i0Wto7ERwFxGEX0HzH6JH35LvAV52Nklsj3MDSk3DdXENrYjvHe1gj1qlDsRncCM5kpSY9ihqKp0fdPGE9iFS1p3N1gIAr4Fy3T+PkwYo0XOQfIzg234RLgUx5M6klJgdNcCkiRg/5HjWkf1QVBUU7GTLeKe5lxfA09CdadkbC61cCdSDi8RyBmOovN8bOwglNaKHgB7x64Ym5qZe8wq4hGb1wJEFzcCGM2p5mNtuXhzvNafnKpj/IpLdUVAUXhO9V+RaRBPa5IFu1AKOlC7qS7dZTVvYjZSU7MilUNsEqhpnBnUzYq62ttle6J6QhAmCmBhvtl74wLxZebAtukp3pisRiERqikB6rR31wEWTnc29zd2jK7Yr8qxoXFhCFPDnf15JF8CGUTyjA9xPR7mfQjnd4M8uq9oWS3nRrViSnfIb1yKvVf2ASRpqzvQW50w39pxVg9k8muMHZ1+xc2AZoIkJMzY4B7hUmgURPpr+RfKVKtEtxtjPRcKYpikhdQYEVxk+fDSfYpPa30Y4MIdvFpWXif/Yk5gMtKe4C5ijEtKj+wNNvJHyVxguWBNWnFoiFORpNt+1VBDc0Ass/UoTczpkOfI0EVCP4+2GiS0vNGuKf1UjyfD8FL
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:LV2PR11MB5975.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(396003)(376002)(366004)(136003)(39860400002)(346002)(451199021)(7696005)(71200400001)(33656002)(26005)(53546011)(9686003)(6506007)(83380400001)(186003)(86362001)(38070700005)(38100700002)(122000001)(55016003)(66476007)(91956017)(76116006)(66946007)(66556008)(66446008)(64756008)(41300700001)(2906002)(316002)(52536014)(19627405001)(15650500001)(8936002)(5660300002)(8676002)(110136005)(19627235002)(478600001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: WkWqCTOjRnabSp3lmTR3rWG1Yki5hkUgVjjMFm8NC25/aNSV9L2f1YXtgGiCa+HxlStCtkwas489NtVUeNvadwwOdpJS0dUH2sxl02z6z4nQ5Ggg0lQ/hxjwbDLmW/7jqPQfOuT4WY4gDPwre0KThf+zyZ6dHVik8yj1FH9kDdAnBWu2qVQyd0Be/b2VkGwUNur16CjeGot47zIY/T3or+53z5VbFAgxGWnOHBh6jTmDG3of/AEHQ/t8wIoCpuRqUyVfCCWSmufMMbytOoSm5zy2TftjZzwux3ftQ/6lnYjLqs1kUMbOkZIxAB+YeHfx5Fy32+1WeMy2EY95cTDOQOABNYgwAhEMwzI/s4Of21OOIWk9M+zBG+Fwxe/johp+9HTb+pE49qIM6sLb/fcjodxcHTHz9jI/oQGHTxcs3tOTs63ruNRnZ/8pZtY//VGah/0iv10GZXDcmoWc1wJs1IOweO2vSjGsq4nVWs1ov+LMp81syqSrbiZqDm42IPshHzu6RtRt+0bzivC9mN90TULXUSMfgtl3vplYFTCx30PbhAIAI4Mx69xT6YI1YuxaT2ZKY6cHftgtyl+mTHcnKEF/mKOn6TSomsi5hkr3xC/7SmeK3O6zEfj5SSplgJD0x0faxGmCYGqkUhsoSZ8TkDa0l4Pv7vlo/WkoTy4Tg+Gy5zb/unqEBUHyIfXGUovaWtTeT23VmOuuYFokhnBHlYk/Q88laXtVyEV+VAABglvXoPBF4J5RCPVGPodK8z4jEbVo7G5d0ESAN8DhRYCFvjigGNNn4Fn1lvez1BUQvtXDhqtworwLmNy1E/iSudPpbufDYzYg8HXW5exfSewoupR1YT7cfRnQr0sCttBS+DewkF5kaswNQDPxO/dEkDeCP32DoFxR6aU96BWnm+73K81AqR7HzQdP4Uk28bmQoIgxVD6RXX9wwhJuAYNg+tEC6jrbggXuz2oEHQb0VqOO2Zb8LA7KbjUgImT4xhPgKNtO6/oSgEqET0XKDJ5BkgjiWBHrAgMDq/moL9XkagdTPKu70PiJt1jtTzaZ65NSL4F7KULO6SfRd2zJVgNy8PHx30Vh7cO3c1kitdecthqu0m+fShzuVJFV6oxUI/3B22VJ3S6ZpubdGh8i+8evZvirfYcb433ZSV4Gw7iVbggnHU1voCjnvZEcvgzgeqobAtUxIfZSf9k9pxiwKoyCkB9K/vFqUIJe9oGt3az+NgUEveaTzM/mCFgLWCCy40XlFxul4VEDQQM+XQ0zHKLum2W02gnpJAlCVW9tTGIgZRY3e3HC+U2okEAwGjkFanlVlzRhSG7seOZnoVABKmyqSUn+wR2eQhb/K3rhfftcY4s4ODndwAhQgg1eJ2tnEtjZvWs63sKyzAVRHlBVxFyl0toIzSC4jRuLNJxFcIhsXVYs2i1RjIe8+RpZ2+1SHuMYnVd/kMJXDM1OcY320GcES8+OkNQF5ctvNWLusfgPhtty2Onlrx2b3RDWVnudQ6TBC58xC1JCtolNuUqAk4ouQurEn7MuP87X/25QCZeOKl7J2eTdxV/IdLFDpIG4OXhE3g1HMjGOl7bkJGowu+7iBiTi1prCM64KgtU3gVkCjbsGaw==
Content-Type: multipart/alternative; boundary="_000_LV2PR11MB59757E27436AC1622562E31AF837ALV2PR11MB5975namp_"
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LV2PR11MB5975.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f7f49fec-7cfa-49d5-61ef-08db83b211eb
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Jul 2023 15:01:43.0954 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: gBVogmZcL3yg5qmDZ+bHMavrsWvLYbAcQNJGJ80cqZa7pJklNmoJpZ1IbgGz/3enIOkU6P8C0qahTCA+8h554xm/4YpkLQ0zXm7Vi7o9z4KSeuxOEJFi+hE761VIJcnd
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR11MB5972
X-Proofpoint-GUID: KU2hmeGjMkwqMu14yUMr4Q73HXIWQCqG
X-Proofpoint-ORIG-GUID: KU2hmeGjMkwqMu14yUMr4Q73HXIWQCqG
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.254,Aquarius:18.0.957,Hydra:6.0.591,FMLib:17.11.176.26 definitions=2023-07-13_05,2023-07-13_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 spamscore=0 malwarescore=0 adultscore=0 phishscore=0 clxscore=1015 impostorscore=0 mlxlogscore=999 suspectscore=0 lowpriorityscore=0 mlxscore=0 priorityscore=1501 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2305260000 definitions=main-2307130132
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/_ZvePi9pYewnCbd026_8GIMo7eY>
Subject: Re: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Jul 2023 15:01:56 -0000

> Thinking some more, I realized that in addition to explicitly considering how issuewild works with this, we also need to consider issueemail.  This does bring up the question of whether these are better as parameters of the various issue tags, or whether we’re better off separating this out into a new "acme-discovery” tag that can be applied across all issuance types.  There are pros and cons.  The parameter method makes it easier to be able to have different issuance policies for web and email, which is the entire reason we have separate tags for each.  But I think it’s likely the same server is going to get populated for all the tags, leading to redundancy and potential maintenance issues keeping them in sync.  Or perhaps there’s both a global setting and parameters, although then you get a lot of additional complexity that probably isn’t worth it.  On balance, my gut feeling is that parameters that are handled uniformly across all three issuance tags is probably the best solution, but it could use more discussion and analysis I think.  So I wanted to bring it up.

I would suggest keeping this simple, the different properties with 'issue' actually meaning 'issuetls' and no way to block all issuance with a simple 'issue' property is already confusing enough.

> The other question that occurred to me last night is since this draft is largely about CAA records and tags, and only linked to the ACME protocol itself in its motivation, LAMPS might actually be a better home for the draft, so it lives in the same WG as all the other CAA documents and registries.  But I don’t have strong feelings about that and if people want to continue discussing it at ACME instead, because that’s the motivating use case, I’m fine with that too.

The goal here is ACME discovery,  the draft mostly specifies how the ACME client should process the CAA records, so I would keep this in the ACME working group unless you want to split this up into multiple standards.

________________________________
From: Tim Hollebeek <tim.hollebeek=40digicert.com@dmarc.ietf.org>
Sent: Thursday, July 13, 2023 16:07
To: Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com>; Seo Suchan <tjtncks@gmail.com>; Mike Ounsworth <Mike.Ounsworth@entrust.com>; acme@ietf.org <acme@ietf.org>
Subject: RE: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt


A few more comments:



Thinking some more, I realized that in addition to explicitly considering how issuewild works with this, we also need to consider issueemail.  This does bring up the question of whether these are better as parameters of the various issue tags, or whether we’re better off separating this out into a new "acme-discovery” tag that can be applied across all issuance types.  There are pros and cons.  The parameter method makes it easier to be able to have different issuance policies for web and email, which is the entire reason we have separate tags for each.  But I think it’s likely the same server is going to get populated for all the tags, leading to redundancy and potential maintenance issues keeping them in sync.  Or perhaps there’s both a global setting and parameters, although then you get a lot of additional complexity that probably isn’t worth it.  On balance, my gut feeling is that parameters that are handled uniformly across all three issuance tags is probably the best solution, but it could use more discussion and analysis I think.  So I wanted to bring it up.



The other question that occurred to me last night is since this draft is largely about CAA records and tags, and only linked to the ACME protocol itself in its motivation, LAMPS might actually be a better home for the draft, so it lives in the same WG as all the other CAA documents and registries.  But I don’t have strong feelings about that and if people want to continue discussing it at ACME instead, because that’s the motivating use case, I’m fine with that too.



-Tim



From: Acme <acme-bounces@ietf.org> On Behalf Of Paul van Brouwershaven
Sent: Thursday, July 13, 2023 5:07 AM
To: Seo Suchan <tjtncks@gmail.com>; Tim Hollebeek <tim.hollebeek@digicert.com>; Mike Ounsworth <Mike.Ounsworth@entrust.com>; acme@ietf.org
Subject: Re: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt



> so It would mean all of parameter definitions can be applied to issuewild too, and if there is only they will be considered?



Yes, the regular CAA selection MUST be followed, or the CA might not be authorized to issue the certificate after all.



The parameters can be applied to any CAA property (issue, issuewild, vmc, issuemail, etc.) as long as the ACME client supports the protocol, and the CA supports the issuance.



________________________________

From: Seo Suchan <tjtncks@gmail.com<mailto:tjtncks@gmail.com>>
Sent: Thursday, July 13, 2023 09:54
To: Paul van Brouwershaven <Paul.vanBrouwershaven@entrust.com<mailto:Paul.vanBrouwershaven@entrust.com>>; Tim Hollebeek <tim.hollebeek@digicert.com<mailto:tim.hollebeek@digicert.com>>; Tim Hollebeek <tim.hollebeek@digicert.com<mailto:tim.hollebeek@digicert.com>>; Mike Ounsworth <Mike.Ounsworth@entrust.com<mailto:Mike.Ounsworth@entrust.com>>; acme@ietf.org<mailto:acme@ietf.org> <acme@ietf.org<mailto:acme@ietf.org>>
Subject: Re: [Acme] [EXTERNAL] New Version Notification for draft-vanbrouwershaven-acme-auto-discovery-00.txt



so It would mean all of parameter definitions can be applied to issuewild too, and if there is only they will be considered?

2023-07-13 오후 4:47에 Paul van Brouwershaven 이(가) 쓴 글:

3.1.1. recommend clarifying the extent to which case matters.  How should

"TRUE" or "True" be handled?

The document now specifies that this must be a lower-case Boolean

4-5. This is WAY in the weeds, and possibly should just be ignored, but

there's actually no requirement that the CA is able to host content at

the domain specified in the CAA tag.  At a minimum, they're only required

to have permission from the domain owner (RFC 8659, first paragraph,

item 2, second clause).  This might actually even happen due to

acquisitions.  In such situations, a CA might actually be unable to host

content on a .well-known URL for a tag it uses.

CAs could instruct the user to use a new CAA issuer-domain and they pro

Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.