Glossary
Certificates
Certificate authority
An organisation that issues TLS certificates after validating control of a name. Which CAs a browser trusts is a decision made by the browser vendor, not by you — CAA is how you narrow it for your own domain.
Defined in CA/Browser Forum Baseline Requirements.
Where this appears
The lessons that use this term, and what each is for.
Advanced Email TrustTwo answers to the same problemSay what MTA-STS and DANE each assert, and which part of the trust they place elsewhere.Advanced Email TrustVMC, CMC, and the trademarkSay what the certificate attests, what it costs, and which authorities issue it.Advanced Email TrustWhat breaksName the failure each advanced control introduces, and how it presents.Domain Security FundamentalsCAA: constraining who may issueWrite a CAA policy for a domain and say exactly which issuance attempts it stops.Domain Security FundamentalsCertificate Transparency as a detection channelRead a CT log entry and say what it does and does not tell you about a domain.DNS Security PractitionerReading a CAA setSay exactly which authorities may issue for a name, given a set of records.DNS Security PractitionerCAA against your own ACME clientWrite a CAA set that constrains issuance without blocking the client that renews your certificates.Domain Abuse & ImpersonationReading a log entryExtract everything a Certificate Transparency entry discloses, including names nobody published.Brand ProtectionCertificate streamsRun a certificate feed as a live channel rather than a periodic search.Brand ProtectionFive partiesName every party who can remove a phishing site and what each is able to act on.