You don't know that even with DNS validated certificates. There's no separate "entity" claim other than "anybody with DNS record modification rights for a given domain".
You can give out the same claim over DNS directly without any extra third party involvement in the form of CA.
You don't know that even with DNS validated certificates. There's no separate "entity" claim other than "anybody with DNS record modification rights for a given domain".
You can give out the same claim over DNS directly without any extra third party involvement in the form of CA.