4 ms·
It's certainly not an interpretation I'd punish a CA for, the language in section 3.2.2.8 is rather ambiguous. Let's Encrypt is running a fail-close setup for
by pfg 8y ago
It's certainly not an interpretation I'd punish a CA for, the language in section 3.2.2.8 is rather ambiguous.
Let's Encrypt is running a fail-close setup for DNSSEC, so I wouldn't quite say it's too unreliable in this particular context. Still, it's quite clear that DNSSEC's complexity is getting in the way of things here. A solution just for this specific use-case would be much simpler overall, and I'm not buying into any of the other benefits DNSSEC claims to bring, so I'd rather just see it die.