Edit report at https://bugs.php.net/bug.php?id=73850&edit=1
ID: 73850
Updated by: krakjoe@php.net
Reported by: marcus at synchromedia dot co dot uk
Summary: dns_get_record lacks support for RFC6844 CAA record
type
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: Network related
Operating System: any
PHP Version: 7.1.0
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
This was merged.
Previous Comments:
------------------------------------------------------------------------
[2017-01-02 11:39:09] marcus at synchromedia dot co dot uk
Description:
------------
The CAA record type is a security related DNS record type used to validate encryption certificate
issuers for a domain. In purpose it has quite a lot in common with HPKP certificate pinning, but
with fewer downsides. Ideally it is combined with DNSSEC.
CAA is defined in RFC 6844: https://tools.ietf.org/html/rfc6844
It defines a new DNS record type with code 257 (see section 7.1 of the RFC)
PHP lacks support for this record type, so it cannot be queried using dns_get_record in PHP.
CAA is not yet seeing widespread take-up, however, it is supported by the letsncrypt.org CA, and
that is becoming very popular - control panels etc that support DNS and TLS configuration are thus
likely to need support for this record type in PHP.
Test script:
---------------
var_dump(dns_get_record('php.net', DNS_CAA));
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73850&edit=1