4 ms·
It's not about proving that you can serve HTTPS, it's about proving that you can legitimately serve HTTPS. I'd find HTTP(S)-based validation ok if CAs wouldn't
by Ao7bei3s 11y ago
It's not about proving that you can serve HTTPS, it's about proving that you can legitimately serve HTTPS.
I'd find HTTP(S)-based validation ok if CAs wouldn't issue certificates with an expiration time past the expiration time of the DNS records.
Of course that would be fairly impractical. But then DNS-based validation exists and doesn't have these problems.
- eridius 11y agoWhat is the difference between serving HTTPS and "legitimately" serving HTTPS? Or to put it another way, what qualifies as "illegitimate" HTTPS?