When a public CA issues TLS certificates, it must validate the domain before issuing a certificate.
The recommendations below apply to public TLS certificates issued by public certificate authorities.
Persistent CA domain validation
Persistent domain validation verifies domain control once and keeps that validation valid over time. Unlike per-issuance validation, which requires a validation step for every certificate request, persistent domain validation removes the need to repeat domain validation for subsequent certificate issuances, renewals, or re-issuances.
Automating CA persistent domain validation with DNS-PERSIST-01
We recommend DNS-PERSIST-01 for public TLS certificates because it enables fully automated domain validation. After you configure the persistent DNS validation record and validate the domain, you won't need manual validation steps for later certificate operations.CSP solutions can then automate the full certificate lifecycle end to end, including:
- Initial certificate issuance
- Certificate renewal
- Certificate re-issuance
This approach provides a hands-off certificate management workflow and removes manual domain validation from each request.
DNS-PERSIST-01 is a CA/Browser Forum-approved domain control validation (DCV) method. The CA/Browser Forum adopted it in Ballot SC-088v3, "DNS TXT Record with Persistent Value DCV Method," and defines it in section 3.2.2.4.22 of the Baseline Requirements for TLS Server Certificates.