TLS Baseline Requirements 2.3.0 consolidate DNSSEC validation rules
SC100 consolidates validation requirements into a new section. Distinguish CA validation duties from your own DNS configuration.
Contents of this article
What happened
On September 7, 2026, the CA/Browser Forum servercert repository released TLS Baseline Requirements 2.3.0. Its SC100 release notes describe DNSSEC clarification and consolidation, moving relevant requirements from sections 3.2.2.4 and 3.2.2.8 into the new section 3.2.2.10.
Implications for website operations
Reorganizing requirements does not mean every website must immediately change its CDN or reissue certificates. Operators should keep validation dependencies healthy: authoritative DNS, CAA, DNSSEC status and automated validation records can all affect issuance and renewal.
Operational next steps
Include certificate renewal checks in DNS migration plans. When changing DNS providers or DNSSEC settings, confirm that parent records and signing configuration agree, then externally test resolution and issuance. Do not delete validation records without checking their dependencies.
