Hacker News new | ask | show | jobs
by Lennie 2943 days ago
Also notice how the plan is to push not only DNS entries but also TLS certificates:

"Right now, people are really keen to get HTTP/2 “out the door,” so a few more advanced (and experimental) features have been left out, such as pushing TLS certificates and DNS entries to the client — both to improve performance. HTTP/3 might include these, if experiments go well."

https://www.mnot.net/blog/2014/01/30/http2_expectations

Some of those things could be used for bootstrapping SNI encryption as well:

https://www.ietf.org/mail-archive/web/tls/current/msg17474.h...