[ale] Let's Encrypt issue starting March 4th

This appears to only be a problem if you publish a CAA record for the domain to which the cert applies.

I looked at CAA records when they first came out and determined they don't have much value as a security mechanism.   

Only the Certificate Authorities (DigiCert, Symantec, LetsEncrypt, etc...) check for CAA to determine if they're allowed to issue for a given domain.   Any CA that doesn't do validation of domain ownership also wouldn't bother to check for CAA.  I've read nothing suggesting anyone other than CAs else is comparing CAA to the actual certificate issuer as a check to verify web traffic is truly authorized.

Domains with a single cert are NOT impacted.

Someone created a site for people to check their LE certs:
