{"id":2605,"date":"2019-10-22T17:05:17","date_gmt":"2019-10-22T09:05:17","guid":{"rendered":"https:\/\/www.mondoze.com\/guide\/?post_type=kb&#038;p=2605"},"modified":"2022-10-05T08:02:49","modified_gmt":"2022-10-05T00:02:49","slug":"certification-authority-authorization-caa-faq","status":"publish","type":"kb","link":"https:\/\/www.mondoze.com\/guide\/kb\/certification-authority-authorization-caa-faq","title":{"rendered":"Certification Authority Authorization (CAA) FAQ"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2605\" class=\"elementor elementor-2605\" data-elementor-settings=\"[]\">\n\t\t\t\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-50c2cd5c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"50c2cd5c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ee1cda4\" data-id=\"ee1cda4\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e47c5c8 elementor-widget elementor-widget-heading\" data-id=\"e47c5c8\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Certification Authority Authorization (CAA)<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3930847e elementor-widget elementor-widget-text-editor\" data-id=\"3930847e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\">\n\t\t\t\t<h3><strong>What is CAA?<\/strong><\/h3><p>A Certificate Authority Authorization (CAA) record allows domain owners to restrict issuance to specified Certificate Authorities (CAs).\u00a0<em>CAA records<\/em>\u00a0prevent CAs from issuing certificates under certain circumstances. \u00a0Refer to RFC 6844 for further details.<\/p><h3><strong>How does Cloudflare evaluate CAA records?<\/strong><\/h3><p><em>CAA records<\/em> are evaluate by a CA, not by Cloudflare.<\/p><p>Setting a\u00a0<em>CAA record<\/em>\u00a0to specify one or more particular CAs has no effect on which CA(s) Cloudflare will use to issue a Universal or Dedicated SSL certificate for your domain.<\/p><h3><strong>Why must I disable Universal SSL if my <em>CAA records<\/em>\u00a0exclude Universal SSL issuance?<\/strong><\/h3><p>Since Universal SSL certificates are share between customers, your <em>CAA records<\/em>\u00a0may prevent issuance of another customer\u2019s Universal SSL. Therefore, Cloudflare must disable Universal SSL for your domain to ensure your\u00a0<em>CAA records<\/em>\u00a0do not affect another customer.<\/p><p><em>CAA records<\/em> are automatically add for the Universal SSL CA providers comodoca.com, digicert.com, and letsencrypt.org if Cloudflare&#8217;s Universal SSL is enable for your domain.<\/p><p>If you do not require Universal SSL from Cloudflare,\u00a0<strong>Disable Universal SSL<\/strong>\u00a0in the\u00a0<strong>Crypto<\/strong>\u00a0app.<\/p><p>Disabling Universal SSL will leave your Cloudflare enable DNS records without SSL support unless you have uploaded acustom SSL certificate (requires Business or Enterprise plan).<\/p><h3><strong>What records are added to keep Universal SSL enabled?<\/strong><\/h3><p>The following DNS records are automatically set if you continue to use Cloudflare\u2019s free Universal SSL certificates:<\/p><pre>example.com. IN CAA 0 issue \"comodoca.com\" example.com. IN CAA 0 issue \"digicert.com\" example.com. IN CAA 0 issue \"letsencrypt.org\" example.com. IN CAA 0 issuewild \"comodoca.com\" example.com. IN CAA 0 issuewild \"digicert.com\" example.com. IN CAA 0 issuewild \"letsencrypt.org\"<\/pre><p>Do not use the\u00a0<em>Only allow wildcards<\/em>\u00a0option for the root record (which returns only\u00a0<em>issuewild<\/em>\u00a0records) for any domain that will use Cloudflare&#8217;s Universal SSL.<\/p><p>Used alone,\u00a0<em>issuewild<\/em>\u00a0only permits wildcard issuance. \u00a0Therefore, Cloudflare cannot add your root domain to the certificate unless you specify the\u00a0<em>Allow wildcards and specific hostnames<\/em>\u00a0option in the\u00a0<strong>Tag<\/strong>\u00a0dropdown:<\/p><p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-2609\" src=\"https:\/\/www.mondoze.com\/guide\/wp-content\/uploads\/2021\/03\/caa1-300x193.png\" alt=\"\" width=\"300\" height=\"193\" \/><\/p><h3><strong>What happens when Universal SSL is disable?<\/strong><\/h3><p>Your domain name is immediately remove from the Universal SSL certificate and your users will observe SSL errors unless you upload a custom SSL certificate (requires Business or Enterprise plan).<\/p><h3><strong>How do I re-enable Universal SSL?<\/strong><\/h3><p>File a support ticket with Cloudflare Support.<\/p><h3><strong>What are the dangers of setting CAA records?<\/strong><\/h3><p>If you are part of a large organization or one where multiple parties are task with obtaining SSL certificates, include <em>CAA records<\/em>\u00a0that allow issuance for all CAs applicable for your organization. \u00a0Failure to do so can inadvertently block SSL issuance for other parts of your organization.<\/p>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Certification Authority Authorization (CAA) What is CAA? A Certificate Authority Authorization (CAA) record allows domain owners to restrict issuance to specified Certificate Authorities (CAs).\u00a0CAA records\u00a0prevent CAs from issuing certificates under certain circumstances. \u00a0Refer to RFC 6844 for further details. How does Cloudflare evaluate CAA records? CAA records are evaluate by a CA, not by Cloudflare. &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.mondoze.com\/guide\/kb\/certification-authority-authorization-caa-faq\"> <span class=\"screen-reader-text\">Certification Authority Authorization (CAA) FAQ<\/span> Read More \u00bb<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[53],"kbtag":[110],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2605"}],"collection":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/comments?post=2605"}],"version-history":[{"count":11,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2605\/revisions"}],"predecessor-version":[{"id":21945,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kb\/2605\/revisions\/21945"}],"wp:attachment":[{"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/media?parent=2605"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=2605"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/kbtag?post=2605"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.mondoze.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=2605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}