LWN.net Logo

HTTPS Everywhere brings HTTPS almost everywhere

HTTPS Everywhere brings HTTPS almost everywhere

Posted Jul 1, 2010 16:19 UTC (Thu) by cortana (subscriber, #24596)
In reply to: HTTPS Everywhere brings HTTPS almost everywhere by cesarb
Parent article: HTTPS Everywhere brings HTTPS almost everywhere

That would be really cool. Such a system could totally replace the role of the CA in verifying that a public key is attached to a particular domain name.

I guess we'll still need CAs to perform detailed identity checks in order to issue the so-called 'extended validation' certificates, for high-security web sites.

I wonder how to get everyone to switch though? The existing CAs will lobby against any change. One advantage of getting certificates via DNSSEC would be that it would finally be possible to actually *revoke* a certificate, something which is basically impossible with the current system, since no one configures their browser to check the CRL of each and every CA that it trusts...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds