Post #3087443
2026-02-27 13:41 UTC
@agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange Yes, the CA/B Forum rules preventing issuing new .arpa certs kick in on March 15th so by mid-year at least the DV versions of these will all be expired.
The issue is at https://github.com/cabforum/servercert/issues/153
and ballot is at https://cabforum.org/2025/11/10/ballot-sc-086v3-sunset-the-inclusion-of-ip-reverse-address-domain-names/
I'm unconvinced that the reasons for doing this are legitimate more than cute/clever, and the benefits of prohibiting outweigh the impacts.
Replies (1)
-
@agowa338@chaos.social 2026-02-27 13:43
@nygren@hachyderm.io @InfobloxThreatIntel@infosec.exchange Well tbh there wasn't really anyone using .arpa domains for more than "funzies" anyway. So getting rid of them is probably the easiest way to eliminate a bunch of edge cases most people kept overlooking...