Jan Wildeboer 😷:krulorange:<p>TIL (Today I learned) about RFC9495 <a href="https://datatracker.ietf.org/doc/rfc9495/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">datatracker.ietf.org/doc/rfc94</span><span class="invisible">95/</span></a> that extends RFC8659 by adding a new CAA property in DNS called "issuemail" that defines wich CA(s) (Certification Authorities) are allowed to create S/MIME eMail certificates for a domain. And if you don't use S/MIME, you should set it to ";" which means that no CA is allowed to do that.</p><p>So I added</p><p>CAA 0 issuemail ";"</p><p>to the dns of my domains until my CA (Certificate Authority) can produce S/MIME certificates.</p><p><a href="https://social.wildeboer.net/tags/SMIME" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SMIME</span></a> <a href="https://social.wildeboer.net/tags/CA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CA</span></a> <a href="https://social.wildeboer.net/tags/NerdCert" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NerdCert</span></a></p>