Why isn't the SSL cert for a server a special kind of DNS record?
Conversation
Notices
-
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 02:17:41 JST Evan Prodromou
-
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse: (selea@social.linux.pizza)'s status on Sunday, 26-Jan-2025 02:17:40 JST :debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
Rather, why is TLSA records adapted?
-
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse: (selea@social.linux.pizza)'s status on Sunday, 26-Jan-2025 03:30:21 JST :debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
TLSA (DANE) - RTC 6698.
Storing TLS-cert in DNS is a bad idea and kinda defeats the purpose.
However, the idea with TLSA-record is that owners of the domain can verify the "visitor" that the certificate is valid - DNSSEC required ofcourse.Postfix already have support for it called DANE, and if I remember correctly - about 0.3% of SMTP-servers online actually implemented it (2019 data)
-
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 03:30:22 JST Evan Prodromou
@selea I don't understand this sentence.
-