TLS Baseline Requirements 2.3.0 consolidate DNSSEC validation rules

SC100 consolidates validation requirements into a new section. Distinguish CA validation duties from your own DNS configuration.

Contents of this article

What happened

On September 7, 2026, the CA/Browser Forum servercert repository released TLS Baseline Requirements 2.3.0. Its SC100 release notes describe DNSSEC clarification and consolidation, moving relevant requirements from sections 3.2.2.4 and 3.2.2.8 into the new section 3.2.2.10.

Implications for website operations

Reorganizing requirements does not mean every website must immediately change its CDN or reissue certificates. Operators should keep validation dependencies healthy: authoritative DNS, CAA, DNSSEC status and automated validation records can all affect issuance and renewal.

Operational next steps

Include certificate renewal checks in DNS migration plans. When changing DNS providers or DNSSEC settings, confirm that parent records and signing configuration agree, then externally test resolution and issuance. Do not delete validation records without checking their dependencies.

Official source

Read the official publication

Back to industry insights Contact technical support