|
|
|
|
|
by agwa
4350 days ago
|
|
> No, DNSSEC has nothing to do with CAs You're interpreting "CA" too literally. DNSSEC doesn't rely on X509 certificate authorities but in effect it relies on an equivalent, in that Verisign is a central authority certifying ownership of all .com domains. |
|
And shouldn't it be possible to implement certificate pinning for whole tlds? Then we'd only have to trust root for unknown tlds.