ISC StormCast for Wednesday, April 26th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 April 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, April 26, 2017 edition of the Sandsenet Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.8 | Today we'll start not with the latest vulnerability or attack, but instead with defensive technology. |
| 0:20.3 | And we do have a great diary here by |
| 0:24.2 | Edward that tells us a little bit more about the CAA records in DNS. CAA stands for certificate |
| 0:31.8 | authority authorization. And if you have not heard about these records, then, well, you're not alone. |
| 0:38.7 | They're still fairly new. |
| 0:40.9 | A lot of registrars do not support them yet, which could turn out to be a problem in September. |
| 0:47.5 | The CA browser organization, which essentially the working group of all the browser makers, |
| 0:54.0 | that decides which certificate |
| 0:55.9 | authorities are added to browsers by default proposed to make this record mandatory starting |
| 1:03.4 | September of this year. So we only got about six months left. The way it's supposed to work is |
| 1:10.6 | this record will advertise in your zone |
| 1:14.1 | who is the certificate authority that's allowed to issue certificates for your domain. Now |
| 1:20.9 | you may list multiple certificate authorities but certificate authorities are not supposed to |
| 1:27.1 | issue you a domain if you don't have the correct CAA record. |
| 1:32.3 | Now overall it would be pretty simple and straightforward to add a record like this to your zone file |
| 1:40.3 | but then again if you for example use GoDad daddy to manage your DNS zone then you just don't |
| 1:47.2 | have the option yet to do so so I'm somewhat skeptical if the September deadline will stand |
| 1:55.5 | but we'll see what happens at least this way I recommend that you read up on this diary by Edward to become familiar |
| 2:04.8 | with the problem and with what this record actually means. There are really two things you can do |
| 2:11.4 | with it. You can list the certificate authorities that you are using. You can also list any |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

