It always seems ridiculous to me that people are coming up with ways to cope with universal CAs (Tack, Convergence, CRLSets, etc.), but can't imagine how to apply those same ideas with a hierarchical system.
CAs are a problem that DNSSEC doesn't solve, but DNSSEC solves tons of other problems without making the CA problem harder.
Comments
It always seems ridiculous to me that people are coming up with ways to cope with universal CAs (Tack, Convergence, CRLSets, etc.), but can't imagine how to apply those same ideas with a hierarchical system.
CAs are a problem that DNSSEC doesn't solve, but DNSSEC solves tons of other problems without making the CA problem harder.