[DNSOP] Re: DNS-designated Public Key Authorities (DKA)

"John R Levine" <[email protected]> 26 Jun 2026 11:27:03 -0400
Newsgroups gmane.ietf.dnsop,gmane.ietf.apps-discuss
Message-ID <[email protected]>
On Fri, 26 Jun 2026, [email protected] wrote:
> From my perspective, and I might be completely wrong.
>
> I am for a DNSSEC-signed record pointing to the DKA to enable the explicit declaration of the endpoint.
> I am for requiring a (trusted-root anchored) CA-signed SSL certificate for the HTTP-endpoint.

> Considering that many organizations outsource their “main” web to a 
> hosting provider that _could_ provide falsified responses something more 
> is needed to start the indication of trust. ....

If the hosting provider is returning malicious content, the organization 
has far more serious problems than a funky key server.

R's,
John

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]