logoalt Hacker News

throw0101dtoday at 7:22 PM1 replyview on HN

> It would be simple today to abolish the use of CAs […]

The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.


Replies

lxgrtoday at 9:17 PM

Exactly, and in some ways, DNS is even more centralized. At least there’s a choice of CAs independent of TLDs.

show 1 reply