Restrict issuers with a CAA record
Add a CAA record to an Edge DNS zone so that only the certificate authorities you name may issue certificates for your domain, from Azion Console or the API.
You can restrict which certificate authorities (CAs) may issue certificates for your domain with a CAA record in Edge DNS, from Azion Console, the Azion CLI, or the Azion API. The record below, 0 issue "letsencrypt.org" on the apex @, names Let’s Encrypt as the CA allowed to issue for example.com. For every CAA tag and value format, refer to Record types.
Your choice of interface sets the prerequisites and the steps to add the record.
Prerequisites
- A zone for your domain in Edge DNS. To create one, refer to Create, edit, or delete a zone.
- No CNAME record on the name that takes the CAA record. A CNAME blocks every other record type on its name.
- The Edit Edge DNS permission. Refer to Teams permissions.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Add the CAA record
The record goes on @, the apex, so it covers example.com. Replace example.com with your domain and letsencrypt.org with the CA you allow.
Certificate Manager requests a workload’s certificates from Let’s Encrypt. While it issues certificates for your domain, keep letsencrypt.org in the record. For how it issues and renews them, refer to Issuance and renewal.
To add the record with the Azion CLI, save the record as caa.json:
Then create the record from the file. Replace <zone-id> with the ID of your zone:
The command prints the ID of the record:
The zone holds the CAA record. Pass the value through --file: --rdata refuses a value that contains double quotes.
A CAA record on a name that holds a CNAME is refused with 19018 CNAME Record Already Exists For Domain. A CNAME on another name of the zone does not block it. Like any change, the record can take a few minutes to reach every nameserver. For how answers are cached, refer to How it works.
Check the record
To ask Azion’s nameserver for the record directly, without your resolver’s cache, replace example.com with your domain:
The answer lists the values of the CAA record. If it lists nothing, refer to Troubleshooting.