ietf-wg-dnsop / draft-ietf-dnsop-domain-verification-techniques

IETF draft surveying DNS domain verification techniques.
https://ietf-wg-dnsop.github.io/draft-ietf-dnsop-domain-verification-techniques/
Other
6 stars 9 forks source link

Domain verification for subtree under or just the domain #16

Closed ShivanKaul closed 3 months ago

ShivanKaul commented 3 years ago

Scope of verification: Let's Encrypt - is only for the domain Google - everything under that domain?

Call this out explicitly in the draft.

Saklad5 commented 1 year ago

I'd say domain verification only proves that control of that exact RRset: any further interpretation is at the discretion of the provider.

enygren commented 3 months ago

https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-account-challenge-01 improves on this as well and we can reference it.

moonshiner commented 3 months ago

I believe it is now https://datatracker.ietf.org/doc/draft-ietf-acme-scoped-dns-challenges/

and it has an example ! yah

moonshiner commented 3 months ago

it is already referenced ACME-SCOPED-CHALLENGE in "Scope Indication" section