DNS operators will be required to verify CAA records when issuing certificates
As a result of additional checks, the CA/B Forum found that section 3.2.2.8 of the current rules for issuing SSL certificates (Baseline Requirements) contains security holes related to CAA verification.
