[DNSOP] Re: [art] Re: DNS-designated Public Key Author ities (DKA)

Bob Traverz <[email protected]> Fri, 26 Jun 2026 14:55:55 -0500
Newsgroups gmane.ietf.dnsop,gmane.ietf.apps-discuss
Message-ID <CAKhC=ah13rPue8wLJihHT2ho3SK-9ZqT+uu3-q5iY1KQgCH=6Q@mail.gmail.com>
>
> Indeed.  MTA-STS is basically an end run around DNSSEC TLSA, because at
> least one large mail provider doesn't sign its DNS.


I can see that. Did that email provider implement MTA-STS?

Regards,

Bob Traverz

On Fri, Jun 26, 2026 at 12:51 PM John R Levine <[email protected]> wrote:

> On Fri, 26 Jun 2026, Bob Traverz wrote:
> > With respect to the DKA discussion, I’d run the “edge-case” test to test
> if
> > a proposed architecture makes sense. Does a domain, to have a DKA,
> > necessarily require a website or other HTTPS assets? If not, there is no
> > inherent dependency between a website and a DKA. Forcing a domain to have
> > an “A” record designating a Https resource just to run a .well-known URL
> > that delivers another endpoint is simply an end-run around the DNS. Feels
> > like a hack rather than a well-designed architecture.
>
> Indeed.  MTA-STS is basically an end run around DNSSEC TLSA, because at
> least one large mail provider doesn't sign its DNS.
>
> You know, all you really need to do is pick a name like dka-server and say
> that the server for example.com is at https://dka-server.example.com.
> All
> done.  If you want to outsource your key server to a shared service, you
> know what CNAMEs are.
>
> R's,
> John
>

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]