Members of the CA/Browser Forum voted in March to run mandatory certificate authority authorization (CAA) checks before issuing any certificate. The system allows domain name holders to specify multiple CAs that can authorize certificates for a domain. By applying this specification, the domain effectively prevents CAs from issuing an authorized certificate in its name. There is no clearly defined policy for how CAA checking will work with the CNAME records stored in the CAA. This means that when given two different CAs on a certificate, it may be unclear which controls issuance.”]
Source: https://securityintelligence.com/news/ssl-certificates-now-need-mandatory-authorization-checks/

