4 ms·
How would you validate whether a certificate was signed by a registrar or not? If the answer is to walk down the DNS tree, then you have basically arrived at D
by ratorx 2y ago
How would you validate whether a certificate was signed by a registrar or not?
If the answer is to walk down the DNS tree, then you have basically arrived at DNSSEC/DANE. However I don’t know enough about it to say why it is not more widely used.
- xorcist 2y agoHow do you validate any certificate? You'd have to trust the registrar, presumably like you trust any one CA today. The web browsers do a decent job keeping up to date with this and new top domains aren't added on a daily basis anyway. Utilizing DNS, whois, or a purpose built protocol directly would alleviate the problem altogether but should probably be done by way of an updated TLS specification. Any realistic migration should probably exist alongside the public CA model for a very long time.
- tptacek 2y agoA recent thread going into details of why (only a tiny fraction of zones are signed, in North America that count has gone sharply down over recent intervals, and browsers don't support it): https://news.ycombinator.com/item?id=41916478 https://news.ycombinator.com/item?id=41916478