4 ms·
> At this point, why not just use DANE Interests of the existing PKI industry may be the source of some friction, but the bigger issue is that DANE depends on
by thayne 6mo ago
> At this point, why not just use DANE
Interests of the existing PKI industry may be the source of some friction, but the bigger issue is that DANE depends on DNSSEC, which is not widely deployed, and sometimes actively avoided due to its complexity and ease of breaking you site.
Don't get me wrong, I'd love it if DANE, or something similar caught on, but I don't think it is practical until something changes to make DNSSEC (or equivalent) common.
- PunchyHamster 6mo ago> Interests of the existing PKI industry may be the source of some friction, but the bigger issue is that DANE depends on DNSSEC, which is not widely deployed, and sometimes actively avoided due to its complexity and ease of breaking you site. I have a feeling it is "actively avoided" because vendors don't want to lose control of the cert ecosystem. Allowing user to just generate a domain for themselves means it will never get logged in central log and so can't be automatically found by crawlers by the big guys
- xorcist 6mo agoThis is public data so the big guys could absoltely crawl it. But we should not underestimate the size of the PKI industry, several large actors make good living from the existing web PKI and they will not change unless their very existence is threatened.
- Parodper 6mo ago> Allowing user to just generate a domain for themselves That's limited mostly by policy[1], the current PKI environment already allows delegating CA for a single domain. [1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-certificate/237578/8 https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...
- PunchyHamster 6mo agoLast time I checked support for that on client side was pretty spotty
- tptacek 6mo agoThere is no support for DANE on the client side!
- jeroenhd 6mo agoIf DANE were to roll out to browsers, I think plenty of people would rather use it than centralizing on Let's Encrypt. DNSSEC isn't easy, but either is certbot. DNSSEC also isn't that hard if you're not self-hosting your DNS servers (and even then it's easy if you pick a modern DNS server). Most domains seem to use their registrars free DNS servers. For those domains, DNSSEC is often just a checkbox. I just activated DNSSEC on three domains by hitting that checkbox. A certbot-style tool can use the same API many existing certbot plugins already provide access to for setting up DANE. However, until browsers actually implement DANE, it's pretty useless. I know some people use it for mail servers (for some reason, don't see why they can't use Let's Encrypt for that) but even there it's optional.
- thayne 6mo ago> DNSSEC also isn't that hard if you're not self-hosting your DNS servers It isn't that hard if: - you use your domain registrar for serving your DNS as well. Even if you aren't "self-hosting", but use a different service for DNS hosting than you registered your domain with, then it can be complicated to coordinate between them. And - your domain registrar makes it easy to set up. For some it is just a checkbox, for others, you have to contact customer support, and sometimes pay more. Also, the server is just half of the problem. It also requires dns resolvers and clients to validate DNSSEC, which often isn't done today, and even when it is, often fails open, because so many domains don't use DNSSEC, and intermediate resolvers don't always support it. Validating DNSSEC can also hurt performance, in part because of the larger response sizes.
- jeroenhd 6mo ago> Even if you aren't "self-hosting", but use a different service for DNS hosting than you registered your domain with, then it can be complicated to coordinate between them Indeed, you'd need to copy-paste four text fields > for others, you have to contact customer support, and sometimes pay more. That's ridiculous, I've never seen any registrar do that. Even if you do choose a terrible registrar, actual DANE rollout in browsers would put pressure on them to get their shit together. As for DNSSEC validation: validation currently seems to happen between 0 to 95% according to https://stats.labs.apnic.net/dnssec https://stats.labs.apnic.net/dnssec Obviously, for DANE to work, verification must happen. DANE-enabled browsers will enforce validation, or fall back to regular TLS (with the scary warnings if someone stripped DNSSEC for a DANE server, as the certificate doesn't work any more). On operating systems that don't bother with DNSSEC validation, browsers can still query the necessary keys. As for performance, DNSSEC does impose extra network traffic, but so does transmitting an intermediate certificate.