Why isn't the SSL cert for a server a special kind of DNS record?
Conversation
Notices
-
Embed this notice
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 02:16:22 JST Evan Prodromou
-
Embed this notice
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse: (selea@social.linux.pizza)'s status on Sunday, 26-Jan-2025 02:17:38 JST :debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
Rather, why is TLSA records adapted?
-
Embed this notice
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 02:35:39 JST Evan Prodromou
@selea I don't understand this sentence.
-
Embed this notice
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 02:38:10 JST Evan Prodromou
https://letsencrypt.org/docs/challenge-types/#dns-01-challenge
-
Embed this notice
Steve Dinn 🇨🇦 (steve@social.dinn.ca)'s status on Sunday, 26-Jan-2025 02:38:11 JST Steve Dinn 🇨🇦
@evan It would make it a pain in the ass to have it automatically renew when it was nearing its expiration. Wait, not everyone uses @letsencrypt ???
In conversation permalink -
Embed this notice
Evan Prodromou (evan@cosocial.ca)'s status on Sunday, 26-Jan-2025 02:38:37 JST Evan Prodromou
@R1Rail That's interesting! I will see if I can give it a try.
In conversation permalink -
Embed this notice
Erwan 🚄 (r1rail@pouet.chapril.org)'s status on Sunday, 26-Jan-2025 02:38:39 JST Erwan 🚄
@evan You can achieve this with the TLSA RR (and then you must use DNSSEC to guarantee - up to a certain kind of certainty - that the genuine DNS answer is returned)
In conversation permalink -
Embed this notice
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse: (selea@social.linux.pizza)'s status on Sunday, 26-Jan-2025 03:30:18 JST :debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
TLSA (DANE) - RTC 6698.
Storing TLS-cert in DNS is a bad idea and kinda defeats the purpose.
However, the idea with TLSA-record is that owners of the domain can verify the "visitor" that the certificate is valid - DNSSEC required ofcourse.Postfix already have support for it called DANE, and if I remember correctly - about 0.3% of SMTP-servers online actually implemented it (2019 data)
In conversation permalink
-
Embed this notice