Post #1661626
2026-03-26 13:13 UTC
@april
Uninformed reply, I havent read the RFCI think if this was only used for fallback this might be ok, but I'm worried there are gonna be cases where this is the only option, and I don't think it's a good idea to force all http clients to also do DNS resolution
Also doesn't dnssec have a completely different model compared to the "standard" root ca infra? I think security people wouldn't like that
Replies (1)
-
@domi@donotsta.re 2026-03-26 13:15
@Mae @april dnssec being different is actually cool. we already maintain that chain of trust for domains, why not use it here problem is, this is signing, not encryption