Reference Source

DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.

For DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue., requirement is DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue; effective date is 2026-03-15; baseline requirements section is 3.2.2.8.1; authority is CA/Browser Forum TLS Baseline Requirements; scope is all publicly-trusted CAs issuing TLS server certificates, recorded from its source on 2026-08-05.

Requirement
DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. verified
Effective date
2026-03-15 verified
Baseline Requirements section
3.2.2.8.1 verified
Authority
CA/Browser Forum TLS Baseline Requirements our reading
Scope
all publicly-trusted CAs issuing TLS server certificates our reading
Sourcecabforum.org
Verified2026-08-05
Review by2026-11-03
DatasetTLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.

What the source says

2026-03-15 | 3.2.2.8.1 | DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.

cabforum.org, retrieved 2026-08-05

Source

Last verified against source: 2026-08-05. Due for re-check by 2026-11-03. This page as Markdown · OKF bundle · full dataset as JSON.