diff --git a/docs/BR.md b/docs/BR.md index 3edd10e4..47db1e17 100644 --- a/docs/BR.md +++ b/docs/BR.md @@ -773,6 +773,9 @@ Effective March 15th, 2026: CAs MUST NOT use local policy to disable DNSSEC vali DNSSEC validation back to the IANA DNSSEC root trust anchor MAY be performed on all DNS queries associated with the validation of domain authorization or control by Remote Network Perspectives used for Multi-Perspective Issuance Corroboration. DNSSEC validation back to the IANA DNSSEC root trust anchor is considered outside the scope of self-audits performed to fulfill the requirements in [Section 8.7](#87-self-audits). + +DNSSEC validation back to the IANA DNSSEC root trust anchor is considered outside the scope of the logging requirements of [Section 5.4.1](#541-types-of-events-recorded). + CAs SHALL maintain a record of which domain validation method, including relevant BR version number, they used to validate every domain. **Note**: FQDNs may be listed in Subscriber Certificates using `dNSName`s in the `subjectAltName` extension or in Subordinate CA Certificates via `dNSName`s in `permittedSubtrees` within the Name Constraints extension.