4 ms·
If your zones are signed with DNSSEC, just add a TLSA record for the self-signed certificates to the zones. Clients with DANE [1] support will then recognize th
by blumentopf 12y ago
If your zones are signed with DNSSEC, just add a TLSA record for the self-signed certificates to the zones. Clients with DANE [1] support will then recognize that the self-signed certificates are valid.
Of course, very few clients support DANE as of yet. Nevertheless, that is the most modern solution and you'll spur adoption of DNSSEC and DANE if you offer it to clients.
[1] https://tools.ietf.org/html/rfc6698 https://tools.ietf.org/html/rfc6698
- Osmium 12y agoOff-topic, but speaking of spurring adoption of DNSSEC: does anyone know of any good (dumbed-down) guides on setting up DNSSEC on personal domains / using dnssec-keygen? I keep seeing it mentioned in HN threads as a Good Thing, and I know my registrar supports it, but they have a big warning: "It is strongly recommended that you do not enable this option unless you have a good understanding of what it is and does: you could easily make your domain name inoperative." which doesn't exactly inspire confidence, especially since most small website owners (such as myself) really don't have a good understanding of it!
- chimeracoder 12y ago> I keep seeing it mentioned in HN threads as a Good Thing, Opinions on DNSSEC are... mixed, to say the least: https://news.ycombinator.com/item?id=5571937 https://news.ycombinator.com/item?id=5571937 As a small website owner, are you using TLS? That's the biggest single thing you should be doing - don't worry about DNSSEC. This depends on what you mean by "small", but IMHO, you don't need DNSSEC. Depending on how small/important your website is, you probably don't even need to bother with DNSCurve either, though you might like to for the fun of it.
- Osmium 12y agoThanks for the link; that's actually very informative. My interest in DNSSEC came from reading that it provided a mechanism to securely transmit SSH host key fingerprints, though I'm not sure if there's a better way of doing that. > As a small website owner, are you using TLS? Yes, but I don't require it. Just a free certificate from StartSSL.
- zhovner 12y agoTry this https://translate.google.com/translate?sl=ru&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fhabrahabr.ru%2Fpost%2F138490%2F&edit-text=&act=url https://translate.google.com/translate?sl=ru&tl=en&js=y&prev...
- asutherland 12y agoAlso somewhat off-topic but interesting in the context of DANE and the cost of certificates. Brian Smith (a mozilla security contributor) recently said the following in a discussion about adding support for invalid/self-signed certificates to the Firefox OS e-mail app. The quote below can be found at the bottom of https://groups.google.com/d/msg/mozilla.dev.platform/lT4Mhi-B1JI/2yRok8FDQroJ https://groups.google.com/d/msg/mozilla.dev.platform/lT4Mhi-... noting that I think the first TLS is meant to be TLD. "Regarding DANE: Any TLS registry can apply to be a trust anchor in Mozilla's CA program and we'll add them if they meet our requirements. We can constrain them to issuing certificates that are trusted only for their own TLDs; we've done this with some CAs in our program already. Any CA can give away free certificates to any subset of websites (e.g. any website within a TLD). Consequently, there really isn't much different about the CA system we already have and DANE, as far as the trust model or costs are concerned."