@a @mwl @colin That's exactly what I'm talking about. And with webpki, controlling the public IP lets you get forged certs unless you're using DNSSEC and CAA to forbid all but specific authorized cert issuance. But with DANE, control of the IP gets you nothing because the key is pinned.