4 ms·
That would be DANE with TLSA (RFC 6698, not the stock ticker symbol). You've still got just another chain of trust with the DNSSEC requirement, and the recent D
by zeeZ 3mo ago
That would be DANE with TLSA (RFC 6698, not the stock ticker symbol). You've still got just another chain of trust with the DNSSEC requirement, and the recent DENIC outage breaking that for the entirety of .de isn't the greatest advertisement :D
- tptacek 3mo agoIt's also a dead letter: browsers won't implement it (they did at one point, and then withdrew it).
- TAlborough 3mo ago[flagged]
- xg15 3mo agoYes, which goes back to the old question: why the heck are we using a bunch of insecure systems with awkward bolted-on workarounds instead of just using DNSSEC?
- deleted 3mo ago[deleted]
- xg15 3mo ago(To explain that some more: The current "way to go" with fully automated cert issuance is delegating its trust to DNS anyway - so we might as well get rid of CAs and use the DNSSEC chain of trust directly, with TLS certs linked to it.)