與 DNS CAA 電話聯絡人進行電話聯絡
Phone Contact with DNS CAA Phone Contact
Confirm the Applicant’s control over the ADN by calling the DNS CAA Phone Contact’s phone number and obtain a confirming response to validate the ADN. Each phone call MAY confirm control of multiple ADNs provided that the same DNS CAA Phone Contact phone number is listed for each ADN being verified and the recipient of the phone call provides a confirming response for each ADN. The relevant CAA Resource Record Set MUST be found using the search algorithm defined in RFC 8659, Section 3.
藉由撥打 DNS CAA 電話聯絡人(DNS CAA Phone Contact)的電話號碼,並取得確認回覆以驗證該經授權網域名稱(Authorization Domain Name,ADN),以確認申請者(Applicant)對經授權網域名稱(ADN)的控管權。每次通話得(MAY)確認多個經授權網域名稱(ADN)的控管權,前提是每一個待驗證之經授權網域名稱(ADN)均列出相同的 DNS CAA 電話聯絡人的號碼,且接聽者對每一個經授權網域名稱(ADN)分別做出確認回覆。相關的 CAA 資源紀錄集(Resource Record Set)應(MUST)使用 RFC 8659 第 3 節 定義的搜尋演算法尋找。
The CA MUST NOT be transferred or request to be transferred as this phone number has been specifically listed for the purposes of Domain Validation.
憑證機構(Certification Authority,CA)不得(MUST NOT)接受電話被轉接,或要求轉接至其他對象,因為該電話號碼是專門為網域驗證(Domain Validation)而列出。
In the event of reaching voicemail, the CA may leave the Random Value and the ADN(s) being validated. The Random Value MUST be returned to the CA to approve the request.
若進入語音信箱,CA 得留下隨機值(Random Value)及正在驗證的經授權網域名稱(ADN)。隨機值應(MUST)被回傳給 CA 以核准驗證請求。
The Random Value SHALL remain valid for use in a confirming response for no more than 30 days from its creation. The CPS MAY specify a shorter validity period for Random Values.
隨機值自建立之日起,用於確認回覆的有效期限應(SHALL)不超過 30 日。憑證實務作業基準(Certification Practice Statement,CPS)得(MAY)規定更短的隨機值有效期限。
CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same selected contact address used for domain validation as the Primary Network Perspective.
使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的網域驗證之聯絡人資訊。
Effective March 15, 2026, this method SHOULD NOT be used to issue Subscriber Certificates.
自 2026-03-15 起,此方法不宜(SHOULD NOT)用於簽發用戶憑證。
Effective March 15, 2027:
- The CA MUST NOT rely on this method.
- Prior validations using this method and validation data gathered according to this method MUST NOT be used to issue Subscriber Certificates.
自 2027-03-15 起:
- CA 不得(MUST NOT)依賴此方法。
- 先前使用此方法進行的驗證,以及依據此方法蒐集的驗證資料,不得(MUST NOT)用於簽發用戶憑證。