-
Notifications
You must be signed in to change notification settings - Fork 846
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
adding CAA record for k8s.io #3179
Conversation
/hold |
checks calendar Hope that's OK? |
Not really. Wanted to remove it when we have enough eyes to monitor this change.
we have 359 days left. |
/hold |
/approve |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: cblecker, jimangel The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
/hold cancel |
Deployed: dig CAA k8s.io
; <<>> DiG 9.10.6 <<>> CAA k8s.io
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29216
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;k8s.io. IN CAA
;; ANSWER SECTION:
k8s.io. 3599 IN CAA 0 issue "amazon.com"
k8s.io. 3599 IN CAA 0 issue "letsencrypt.org"
k8s.io. 3599 IN CAA 0 issue "pki.goog"
;; Query time: 54 msec
;; SERVER: 192.168.1.99#53(192.168.1.99)
;; WHEN: Mon Mar 07 08:15:46 CET 2022
;; MSG SIZE rcvd: 125 |
This is the tail-end of the CAA efforts I started in #1849. First we did kubernetes.io, now this PR is for k8s.io.
An interesting thing to note, I found
amazon.com
listed when I searched the transparency logs but checking again today (9 months later) I did not see it.We did identity in a test-infra call that the source was for kops e2e testing (link).
In any event, I don't think it hurts to keep it in but I think we can remove it if new certs haven't been issued in awhile.
/cc @celestehorgan
/milestone v1.24