|
|
|
|
|
by Eikon
482 days ago
|
|
Supporting DANE means you need to maintain both traditional CA validation and DANE simultaneously. This may be controversial, but I believe that with CT logs already in place, DANE could potentially reduce security by leaving you without an audit trail of certificates issued to your hosts. If you actively monitor certificate issuance to your hosts using CT, you are in a much better security posture than what DANE would provide you with. People praising DANE seem to be doing so as a political statement ("I don't want a 3rd party") rather than making a technical point. |
|