Skip to content
Ulrich Berntien edited this page Sep 4, 2020 · 1 revision

TWA-0601

Message

"No CAA records found"

Explanation

No Certificate Authority Authorization (CAA) record could be get from the Domain Name Server (DNS).

A domain owner specifies in the CAA record which Certificate Authorities (CAs) are allowed to issue certificates containing the domain name. The Certification Authority Browser Forum (CA/Browser Forum) recommended that all of his members must check the CAA record before creating a TLS certification file. The check by the CAA record hinder attackers to get a valid certificate for redirect HTTPS connections by a man-in-the-middle attack.

Remediation

You can create a CAA record online with the CAA Record Helper. If your provider is not supported by the CAA Record Helper, contact your provider direct to add a CAA record for your domain.

See

Clone this wiki locally