Conversation

Googlers, is there any official position on why still ignores DANE on outgoing mail and/or why doesn't publish DANE (a DANE-TA record pinning to Google's root CA would be trivial to publish) for incoming mail?
2
8
Replying to and
Wow, and google\.com isn't either. Ick. I wonder if they have some massive infrastructure problem that prevents it or if this is more ideological (possibly with underlying commercial reason) opposition to DNSSEC...
1
I can do key rotations by hand without having to worry about the Let's Encrypt renewal schedule, so using Web PKI isn't a hassle. I have no reason to host a web server on the same domain so I don't have a reason to care that the certificates aren't specific to SMTP or HTTP.
1
Show replies