Skip to content

Comment on Setting up a trusted, self-signed SSL/TLS certificate authority in Linuxparent

Comments

Is it coming? I notice that OpenSSL now has support for raw public keys.

The spec (RFC 7250, "Using Raw Public Keys in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)") suggests DANE/DNSSEC as a mechanism to bind identities to public keys (section 6).

https://datatracker.ietf.org/doc/html/rfc7250

Will this really be simpler?

It is not coming. Browsers are unlikely to support DANE (Chrome briefly did, and then pulled support, IIRC).

Simpler and faster I hope.

In fact, the slowness and complexity of DANE is a big part of why it got pulled.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.