diff --git a/static/features.html b/static/features.html index 12407b64..44633f19 100644 --- a/static/features.html +++ b/static/features.html @@ -211,10 +211,13 @@
  • Strong cipher configurations for all of our services (SSH, TLS, etc.) with only modern AEAD ciphers providing forward secrecy
  • Our web services use OCSP stapling with Must-Staple
  • -
  • DNSSEC implemented for all of our domains, which is particularly important - for securing email due to it relying on DNS records
  • -
  • DANE TLSA records for pinning keys for all our TLS services (mostly helps - to secure email due to lack of browser support)
  • +
  • DNSSEC implemented for all of our domains
  • +
  • DNS Certification Authority Authorization (CAA) records for all of our + domains permitting only Let's Encrypt to issue certificates with fully + integrated support for the experimental accounturi and + validationmethods pinning our Let's Encrypt accounts as the only ones + allowed to issue certificates
  • +
  • DANE TLSA records for pinning keys for all our TLS services
  • Our mail server enforces DNSSEC/DANE to provide authenticated encryption when sending mail including alert messages from the attestation service
  • SSHFP across all domains for pinning SSH keys