Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CAA Record - Missing Digicert account ID for managed certificates #122852

Closed
michaelpfister opened this issue May 28, 2024 · 2 comments
Closed

CAA Record - Missing Digicert account ID for managed certificates #122852

michaelpfister opened this issue May 28, 2024 · 2 comments

Comments

@michaelpfister
Copy link

As for security reasons we have limited our CAA records to specific Digicert accounts.

As for example:
example.com. 28800 IN CAA 0 issue "digicert.com; account=abc1___d234"

In combination with managed certificates this causes a permission issue as expected.
Would it be possible, to include Microsoft's account id within the documentation? This would allow security sensitive customers to extend their CAA records with the specific Digicert account id of Microsoft without having to open it for all Digicert accounts.

The domain verification process built into the Azure App Services already ensures the needed security level, thus allowing Microsoft's account id is the better option than allowing all Digicert accounts.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@PesalaPavan
Copy link
Contributor

@michaelpfister
Thanks for your feedback! We will investigate and update as appropriate.

@msangapu-msft
Copy link
Contributor

We've added this to our backlog to review and update as necessary. #please-close

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants