logoalt Hacker News

cyberaxyesterday at 7:53 PM1 replyview on HN

Sure. It's yet another advantage of doing True DANE. But it still requires DNS to be reliable for the certificate issuance to work, there's no way around it.

So why not cut out the middleman?

(And the answer right now is "legacy compatibility")


Replies

tptacekyesterday at 7:55 PM

I mean, the reason not to do DANE is that nobody will DNSSEC-sign, because DNSSEC signing is dangerous.

show 1 reply