Certificate Authority Authorization (CAA) is a type of DNS record that allows the domain owners to specify which Certificate Authority (CA) can issue SSL certificates for the domain.
A secure connection to a service requires SSL/TLS certificates to ensure the identity of the host and establish a secure channel. Not having CAA records can cause a security risk as anybody can generate a Certificate Signing Request (CSR) for the domain and get the certificate signed by any CA.
CAA records provide an extra layer of protection to your web presence by allowing the domain owner to declare which certificate authorities are allowed to issue a certificate for the domain. If there is a request for a certificate from a non-authorized CA, then the CAA record notifies the domain owner about the same. If a CAA record is not present for a domain, any CA is allowed to issue the certificate for that domain.
The NetScaler appliance supports DNS CAA records in the following modes:
-
Proxy: The appliance caches CAA record response from back-end servers and responds to further queries of the same type from the cache.
-
ADNS: The appliance responds to the CAA record type DNS queries from the configured DNS records.
Note: