# DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. — TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

For DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue., requirement is DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue; effective date is 2026-03-15; baseline requirements section is 3.2.2.8.1; authority is CA/Browser Forum TLS Baseline Requirements; scope is all publicly-trusted CAs issuing TLS server certificates, recorded from its source on 2026-08-05.

- **Requirement:** DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue. _(verified: appears in the quote below)_
- **Effective date:** 2026-03-15 _(verified: appears in the quote below)_
- **Baseline Requirements section:** 3.2.2.8.1 _(verified: appears in the quote below)_
- **Authority:** CA/Browser Forum TLS Baseline Requirements _(our reading, not quoted from the source)_
- **Scope:** all publicly-trusted CAs issuing TLS server certificates _(our reading, not quoted from the source)_

## What the source says

> 2026-03-15 | 3.2.2.8.1 | DNSSEC-validation errors observed by the Primary Network Perspective (e.g., SERVFAIL) MUST NOT be treated as permission to issue.

## Source

- https://cabforum.org/working-groups/server/baseline-requirements/requirements/

Last verified: 2026-08-05. Review by: 2026-11-03.
Part of [TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)](https://referencesource.org/tls-certificate-requirement-effective-dates/).
