Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seems like you could accomplish the same thing by CA pinning your site to Verisign (who runs the DNSSEC root).


That and an expensive *.example.com certificate would get you half of the way there. You still wouldn't be able to be your own CA, signing certificates for foo.example.com that other people can use. And it would require everyone to buy certificates from Verisign.

Nowadays national governments already setup their own CAs because they want to be able to issue certificates for all sorts of government organizations. With the setup I'm suggesting Germany would get .de signed, then they could sign gov.de and then have gov.de sign someagency.gov.de. somecompany.de would get their certificate from the DE registrar when they sign up for the domain and also be able to issue somepartner.somecompany.de or jabber.somecomapny.de certificates that if discovered only compromise part of their network, unlike having a wildcard certificate installed on every server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: