About CAA Records

Hi all,

I recently had customer request to assist in configuring Certification Authority Authorization (CAA) DNS resource record in Infoblox.

Based on the guide below it seems straight forward

https://docs.infoblox.com/space/nios90/1422590540/Adding%2BCAA%2BRecords

However, since my customer has about 5 different CA providers, i wonder

  1. Do we need to create a separate CAA DNS record for each CA provider?
  2. What if we remain empty under Certificate Authority field instead of specific the CA provider? Will it causing any operation risk?
  3. Specifically, would an empty Certificate Authority field prevent all CAs from issuing certificates, or would it allow certificate issuance by any CA?

I wondering if anyone can share their real life experience on this, as this is my first time dealing with this type of CAA records.

Thank you for sharing your opinion.

Tagged:

Answers