4 ms·
This was proposed already in 2012 with RFC6698. DNS based Authentication of Domain Entries, DANE. Hasn't really gone anywhere of importance. I personally thin
by herio 6y ago
This was proposed already in 2012 with RFC6698. DNS based Authentication of Domain Entries, DANE.
Hasn't really gone anywhere of importance.
I personally think there's been a few factors as to why:
* Distrust of DNSSEC and centralized authority.
* Lagging DNSSEC deployment, not just in DNS but also in clients and applications.
* Needs another DNS lookup on connection to validate certs, adding lag. I think it probably needs stapling support in some form just like cert validity checking.
There's also been follow up RFC detailing it's use for SMTP, SRV records and PGP.