Certificates
- Version
- v1
- In force since
- Not yet
- Next review
- At adoption
- Snapshot
- None yet
- Adopted by
- Proposed for founding adoption
- Signature
- At adoption
- Log entry
- Not appended yet
- Binding text
- English
Proposed, not in force
Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.
Scope
This policy binds the GOpenCDR certificate authority, which issues TLS server certificates for names in GOpenCDR TLDs and for nothing else. It is not part of the public web PKI, and a person trusts it only by installing its root after a confirmation that says what that means.
Name constraints
Every CA certificate carries a critical name constraints extension that permits only the current GOpenCDR TLDs as DNS names and excludes every IPv4 and IPv6 range.
Rule ca.name_constraints. Limits: No scope may widen the permitted set beyond the TLDs in the root.
The root is re-issued with the same key whenever the set of TLDs changes, and each re-issued root is published through the channels P-2 8.1 names.
A TLD in sunset leaves the name constraints before its IANA delegation, so that no certificate for a name in it validates against a current root.
Issuance
Certificates are issued only through ACME, RFC 8555, after challenges whose every DNS lookup validates with DNSSEC against the GOpenCDR anchors. A wildcard name needs a DNS challenge.
Rule ca.validation.
CAA is checked for every name through validated lookups, and a record that does not permit the GOpenCDR CA stops the issuance.
Rule ca.caa.
A certificate is valid for at most 45 daysfixed.
Every certificate is logged in the GOpenCDR certificate transparency log before it is used.
Rule ca.ct.
Revocation
Status is published only through revocation lists, renewed at least every 24 hoursfixed and within 1 hourfixed of a revocation. There is no OCSP.
A certificate is revoked within 24 hoursfixed of establishing that its key is compromised, that its subscriber no longer controls a name in it, that a name in it was withdrawn or its TLD left GOpenCDR, that it was issued wrongly, that the subscriber agreement was broken, or that a court or an authority orders it.