[DNSOP] Re: DNS-designated Public Key Authorities (DKA)
"John R Levine" <[email protected]> 26 Jun 2026 11:27:03 -0400
| Newsgroups | gmane.ietf.dnsop,gmane.ietf.apps-discuss |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 26 Jun 2026, [email protected] wrote: > From my perspective, and I might be completely wrong. > > I am for a DNSSEC-signed record pointing to the DKA to enable the explicit declaration of the endpoint. > I am for requiring a (trusted-root anchored) CA-signed SSL certificate for the HTTP-endpoint. > Considering that many organizations outsource their “main” web to a > hosting provider that _could_ provide falsified responses something more > is needed to start the indication of trust. .... If the hosting provider is returning malicious content, the organization has far more serious problems than a funky key server. R's, John _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]