4 ms·
DANE might provide a solution. See specifically the section https://tools.ietf.org/html/rfc6698#section-2.1.1 https://tools.ietf.org/html/rfc6698#section-2.1.1,
by aeden 9y ago
DANE might provide a solution. See specifically the section https://tools.ietf.org/html/rfc6698#section-2.1.1 https://tools.ietf.org/html/rfc6698#section-2.1.1, certificate usage 3:
3 -- Certificate usage 3 is used to specify a certificate, or the public key of such a certificate, that MUST match the end entity certificate given by the server in TLS. This certificate usage is sometimes referred to as "domain-issued certificate" because it allows for a domain name administrator to issue certificates for a domain without involving a third-party CA.
- tscs37 9y agoThis would need DNS to be secured though and DNSSEC is still a bit of a mess last I checked and not enabled for a majority of DNS traffic.
- aeden 9y agoDNSSEC support is increasing each year, but that's just one issue. DANE would also need to be implemented by browsers for full adoption, not just as a plugin to specific browsers. Then again, I was responding to the question about an RFC or other standard, not whether it was feasible today. ;-)
- tscs37 9y agoIt would be feasible if DNSSEC wasn't a total mess, tbh. The support for it is still abysmal and a lot of resolvers (including the one in my router) can't handle DNSSEC responses at all. I think using DNS over HTTPS in conjunction with signing the response is going to be more viable since you don't have 200 ways a middle box will break it.
- tptacek 9y agoIf you want to sign over the security of the Web PKI to the United States Government, DANE is a pretty effective way to accomplish that. It is, essentially, an Internet key escrow scheme.