3 ms·
The main limitation is the incredibly opaque and brittle nature of putting keys in DNS. We've spent a decade and a half slowly making the Web PKI more agile an
by dadrian 2y ago
The main limitation is the incredibly opaque and brittle nature of putting keys in DNS.
We've spent a decade and a half slowly making the Web PKI more agile and more transparent by reducing key lifetimes, expanding automation support, and integrating certificate transparency.
None of that exists for DNS, largely by design.