|
|
|
|
|
by lizardactivist
1424 days ago
|
|
A very big security problem with current domain certificates is that browsers accept any certificate for any domain, as long as they trust the issuer. There is no concept or notion of who is supposed to have issued the certificate. |
|
CAA records provide some extra defence (https://en.m.wikipedia.org/wiki/DNS_Certification_Authority_...).
It’s not perfect, but it’s getting better.