LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

Appraisal of DNSSEC-based certificate verification

Appraisal of DNSSEC-based certificate verification

Posted Sep 27, 2013 10:35 UTC (Fri) by jschrod (subscriber, #1646)
In reply to: Appraisal of DNSSEC-based certificate verification by error27
Parent article: Encouraging a wider view

I don't understand the hyperbole of that article.

Yes, MarkMonitor is a registrar. Google and others need a registrar for their domain names. They chose one. The registrar could set up false name server delegation records. Well, news at 11. That's why we want DNSSEC.

And while they might be potentially a CA at the same time, they're not an approved Firefox CA, AFAICS. I don't have Chrome or a current IE fired up now, is MarkMonitor really an approved CA there?


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds