Point of DNSSEC?
Posted Sep 26, 2007 13:42 UTC (Wed) by job
In reply to: Point of DNSSEC?
Parent article: What to do about DNS?
Sorry for the late answer, but you fail to see the distinction between the encryption protocol and the key distribution. With DNSSEC in place, SSL still works just as before, but instead of trusting CAs you trust the DNS root certificate. The delegation then follows the hierarchical DNS tree. It has been shown again and again that the CA trust model is flawed. With DNSSEC, the person in control of the domain name is also in control of the signing keys for that particular domain.
to post comments)