From c67329b0b0bd23c19be3a6f8c8b92073de5f1f25 Mon Sep 17 00:00:00 2001
From: Julien Cristau <jcristau@debian.org>
Date: Sat, 9 Sep 2017 13:03:58 +0200
Subject: [PATCH] Add CAA records to debian.org zone

---
 debian.org | 54 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 54 insertions(+)

diff --git a/debian.org b/debian.org
index 4a2051d..51ac8d9 100644
--- a/debian.org
+++ b/debian.org
@@ -21,6 +21,10 @@ $TTL 8h
 @			IN	MX	0 mailly.debian.org.
 			IN	MX	0 muffat.debian.org.
 
+@			IN	CAA	0 iodef "mailto:dsa@debian.org"
+@			IN	CAA	0 issue "letsencrypt.org"
+@			IN	CAA	0 issue "amazon.com"       ; for cdn-aws.deb.d.o
+
 ; nameserver services provided by netnod.se
 dnsnode.debian.org.	IN	A	194.146.106.126
 			IN	AAAA	2001:67c:1010:32::53
@@ -1011,6 +1015,7 @@ $TTL 10m
 ;==========
 
 $ORIGIN at.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.debian.at.
 ;ftp	300	IN	CNAME	klecker-ftp.debian.org.
 http		IN	CNAME	ftp
@@ -1018,6 +1023,7 @@ cdimage		IN	CNAME	cdimage.debian.at.
 ;cdimage	300	IN	CNAME	cdimage.debian.org.
 www	300	IN	CNAME	www.debian.org.
 $ORIGIN au.debian.org.
+@		IN	CAA	0 issue ";"
 ; ftp		IN	CNAME	mirror.linux.org.au. ; FIXME
 ; ftp		IN	CNAME	mirror.aarnet.edu.au. ; FIXME
 ;ftp		IN	A	115.126.160.7	; debian.nautile.nc / ftp.nc.d.o
@@ -1027,20 +1033,26 @@ ftp		IN	A	218.100.43.30	; mirror.waia.asn.au.
 ftp.wa		IN	A	218.100.43.30	; mirror.waia.asn.au.
 ;ftp.wa		IN	CNAME	mirror.linux.org.au.
 $ORIGIN ba.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	mirror.debian.com.ba.
 $ORIGIN be.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp	300	IN	CNAME	ftp.nl.debian.org.
 ftp	300	IN	A	195.234.45.114    ; mirror.as35701.net
 ftp	300	IN	AAAA	2a01:70:ffff:1::2 ; mirror.as35701.net
 $ORIGIN bg.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.mobiltel.bg.
 www		IN	CNAME	www.debian.org.
 $ORIGIN br.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.c3sl.ufpr.br.  ; Marcos Castilho <marcos@inf.ufpr.br>
 www		IN	CNAME	www.debian.org.
 $ORIGIN by.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.mgts.by. ; Evgeniy Kozhuhovskiy  <ftpadm@mgts.by>
 $ORIGIN ca.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	A	206.167.141.10	; ftp1.ca
 ftp		IN	A	192.175.120.168	; debian.mirror.iweb.ca.
 ftp		IN	AAAA	2607:f748:10:12::deb:1	; debian.mirror.iweb.ca.
@@ -1053,22 +1065,27 @@ ftp2		IN	CNAME	debian.mirror.iweb.ca.
 ftp3		IN	CNAME	ftp2
 ftp4		IN	CNAME	debian.mirror.rafal.ca.
 $ORIGIN ch.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.ethz.ch.
 ;ftp	60	IN	CNAME	mirror.switch.ch.
 ;ftp	60	IN	CNAME	klecker-ftp.debian.org.
 $ORIGIN cl.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	CNAME	debian.c3sl.ufpr.br. ; ftp.br.debian.org.
 ftp		IN	A	200.75.30.181	; debian.netlinux.cl.
 ftp1		IN	CNAME	debian.netlinux.cl.
 ftp2		IN	CNAME	ftp1
 $ORIGIN cn.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	mirrors.ustc.edu.cn. ; mirrors@ustc.edu.cn
 ftp2		IN      CNAME	mirrors.tuna.tsinghua.edu.cn.
 www		IN	CNAME	www.debian.org.
 $ORIGIN cz.debian.org.
+@		IN	CAA	0 issue ";"
 ; Dan Ohnesorg <Dan@ohnesorg.cz>
 ftp		IN	CNAME	debiancz.debian.cz.
 $ORIGIN de.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	141.76.2.4
 ftp1		IN	CNAME	ftp
 ftp2		IN	CNAME	ftp.halifax.rwth-aachen.de.
@@ -1076,113 +1093,150 @@ ftp2		IN	CNAME	ftp.halifax.rwth-aachen.de.
 ;ftp2	300	IN	CNAME	klecker-ftp.debian.org.
 www		IN	CNAME	www.debian.org.
 $ORIGIN dk.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	mirrors.dotsrc.org.
 $ORIGIN ee.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.aso.ee.
 $ORIGIN es.debian.org.
+@		IN	CAA	0 issue ";"
 ; ftp		IN	A	163.117.156.54 ; ftp.gul(.uc3m).es
 ; ftp		IN	A	130.206.1.5 ; ftp.rediris.es
 ftp		IN	A	82.194.78.250 ; ulises.hostalia.com <jfs@debian.org>
 
 www		IN	CNAME	www.debian.org.
 $ORIGIN fi.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	130.230.54.99
 		IN	AAAA	2001:708:310:54::99
 
 $ORIGIN fr.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.proxad.net.
 ;ftp2		IN	CNAME	ftp.oleane.net.
 ftp2		IN	CNAME	debian.proxad.net.
 www		IN	CNAME	www.debian.org.
 $ORIGIN gr.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	patroklos.noc.ntua.gr.
 $ORIGIN hk.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	A	202.134.73.139 ; Anthony Wong <ypwong@debian.org>
 ftp		IN	CNAME	ftp.jaist.ac.jp. ; ftp.jp.debian.org.
 www		IN	CNAME	www.debian.org.
 $ORIGIN hr.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	161.53.160.11
 		IN	AAAA	2001:b68:ff:1::11
 $ORIGIN hu.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.fsn.hu.
 $ORIGIN id.debian.org.
+@		IN	CAA	0 issue ";"
 www		IN	CNAME	www.debian.org.
 $ORIGIN ie.debian.org.
+@		IN	CAA	0 issue ";"
 ftp	300	IN	CNAME	debian.heanet.ie.  ; Colm MacCarthaigh <colm.maccarthaigh@heanet.ie>
 ; ftp	300	IN	CNAME	ftp.debian.org.
 $ORIGIN ir.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	188.253.2.125 ; debian.asis.io, would cname, but the nameservers are not really all good; factoreal@asis.io
 $ORIGIN is.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.simnet.is.
 $ORIGIN it.debian.org.
+@		IN	CAA	0 issue ";"
 ; ftp		IN	CNAME	debian.ftp.bofh.it.
 ftp     300	IN	CNAME	ftp.debian.org.
 $ORIGIN jp.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	cdn.debian.or.jp.
 ftp2		IN	CNAME	cdn.debian.or.jp.
 www		IN	CNAME	www.debian.org.
 $ORIGIN kr.debian.org.
+@		IN	CAA	0 issue ";"
 ftp	300	IN	CNAME	ftp.kaist.ac.kr.
 $ORIGIN lt.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.mirror.vu.lt. ; Arnoldas Sareckis <hostmaster@vu.lt>
 $ORIGIN md.debian.org.
+@		IN	CAA	0 issue ";"
 ftp	300	IN	CNAME	mirror.as43289.net. ; Sven Wiese <s.wiese@trabia.com>
 $ORIGIN mx.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	CNAME	nisamox.fciencias.unam.mx. ; FIXME
 ftp		IN	CNAME	mmc.geofisica.unam.mx. ; FIXME
 $ORIGIN nc.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	103.2.186.80			; debian.nautile.nc
 		IN	A	103.2.186.81			; debian.nautile.nc
 		IN	AAAA	2404:e400:c::443:1		; debian.nautile.nc
 		IN	AAAA	2404:e400:c::443:2		; debian.nautile.nc
 $ORIGIN nl.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	130.89.149.21 ; debian.snt.utwente.nl
 		IN	AAAA	2001:67c:2564:a120::21 ; debian.snt.utwente.nl
 ;ftp		IN	CNAME	klecker-ftp.debian.org.
 www		IN	CNAME	www.debian.org.
 $ORIGIN no.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	CNAME	debianmirror.uio.no.
 ftp		IN	CNAME	ftp.se.debian.org.
 $ORIGIN nz.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.citylink.co.nz.
 $ORIGIN pl.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	A	153.19.251.221 ; Michal Bialoskorski <skorka@task.gda.pl>
 		IN	AAAA	2001:4070:1::fafb ; Michal Bialoskorski <skorka@task.gda.pl>
 www		IN	CNAME	www.debian.org.
 $ORIGIN pt.debian.org.
+@		IN	CAA	0 issue ";"
 ;ftp		IN	CNAME	info.uevora.pt.  ; Miguel Ramos <miguel@uevora.pt>
 ftp		IN	CNAME	debian.uevora.pt.  ; Tiago Fernandes
 $ORIGIN ro.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.upcnet.ro. ; Imre Gergely <imre.gergely@upc.ro>
 $ORIGIN ru.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	mirror.mephi.ru. ; Andrew Savchenko <aasavchenko@mephi.ru>
 www		IN	CNAME	www.debian.org.
 $ORIGIN se.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.acc.umu.se.
 ;ftp	60	IN	CNAME	klecker-ftp.debian.org.
 $ORIGIN sg.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME   mirror.0x.sg. ; Andrew Yong <me@ndoo.sg>
 $ORIGIN si.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debmirror.amis.net.	; debian-mirrors@amis.si
 $ORIGIN sk.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	mirrors.gts.sk.
 ; ftp		IN	CNAME	mirrors.nextra.sk. ; FIXME
 $ORIGIN sv.debian.org.
+@		IN	CAA	0 issue ";"
 ; ftp		IN	CNAME	mirror.salud.gob.sv.	; mirror@salud.gob.sv; Adolfo Maltez <fmaltez@salud.gob.sv>
 ftp	300	IN	CNAME	klecker-ftp.debian.org.
 $ORIGIN tr.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.linux.org.tr.
 ; Andrew Lee <andrew@linux.org.tw>
 $ORIGIN tw.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	debian.linux.org.tw.
 $ORIGIN ua.debian.org.
+@		IN	CAA	0 issue ";"
 ftp		IN	CNAME	ftp.debian.org.ua.
 www		IN	CNAME	www.debian.org.
 $ORIGIN uk.debian.org.
+@		IN	CAA	0 issue ";"
 ftp	300	IN	CNAME	debian.hands.com.
 ;ftp	300	IN	CNAME	mirror.bytemark.co.uk.	; backup
 www		IN	CNAME	www.debian.org.
 $ORIGIN us.debian.org.
+@		IN	CAA	0 issue ";"
 ftp	300	IN	A	64.50.236.52		; ftp-chi.osuosl.org
 ftp1		IN	A	64.50.236.52		; ftp-chi.osuosl.org
 ftp	300	IN	A	64.50.233.100		; ftp-nyc.osuosl.org
-- 
2.11.0

