3 ms·
I'm sorry, but doesn't DANE RFC (DNS-based check of certs validity) solve the same problem and already implemented in Chrome and (via a plugin) Firefox? With D
by rfctr 13y ago
I'm sorry, but doesn't DANE RFC (DNS-based check of certs validity) solve the same problem and already implemented in Chrome and (via a plugin) Firefox?
With DANE, one doesn't even need CA to issue the cert -- self-signed will work just fine.
https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na...
- jcase 13y agoDANE isn't without its own problems. Moxie Marlinspike wrote an excellent blog post about it. http://www.thoughtcrime.org/blog/ssl-and-the-future-of-authenticity/#dane_dnssec_and_ssl_authenticity http://www.thoughtcrime.org/blog/ssl-and-the-future-of-authe...