Req #73850 [Opn->Csd]: dns_get_record lacks support for RFC6844 CAA record type

From: Date: Wed, 18 Jan 2017 18:41:44 +0000
Subject: Req #73850 [Opn->Csd]: dns_get_record lacks support for RFC6844 CAA record type
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206727@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73850&edit=1

 ID:                 73850
 Updated by:         krakjoe@php.net
 Reported by:        marcus at synchromedia dot co dot uk
 Summary:            dns_get_record lacks support for RFC6844 CAA record
                     type
-Status:             Open
+Status:             Closed
 Type:               Feature/Change Request
 Package:            Network related
 Operating System:   any
 PHP Version:        7.1.0
-Assigned To:        
+Assigned To:        krakjoe
 Block user comment: N
 Private report:     N

 New Comment:

The fix for this bug has been committed.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.

 For Windows:

http://windows.php.net/snapshots/
 
Thank you for the report, and for helping us make PHP better.

This was merged.


Previous Comments:
------------------------------------------------------------------------
[2017-01-02 11:39:09] marcus at synchromedia dot co dot uk

Description:
------------
The CAA record type is a security related DNS record type used to validate encryption  certificate
issuers for a domain. In purpose it has quite a lot in common with HPKP certificate pinning, but
with fewer downsides. Ideally it is combined with DNSSEC.

CAA is defined in RFC 6844: https://tools.ietf.org/html/rfc6844

It defines a new DNS record type with code 257 (see section 7.1 of the RFC)

PHP lacks support for this record type, so it cannot be queried using dns_get_record in PHP.

CAA is not yet seeing widespread take-up, however, it is supported by the letsncrypt.org CA, and
that is becoming very popular - control panels etc that support DNS and TLS configuration are thus
likely to need support for this record type in PHP.

Test script:
---------------
var_dump(dns_get_record('php.net', DNS_CAA));



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73850&edit=1


Thread (1 message)

  • krakjoe@php.net
  • Unknown Message
    • krakjoe@php.net
« previous php.bugs (#206727) next »