Conversation

Googlers, is there any official position on why still ignores DANE on outgoing mail and/or why doesn't publish DANE (a DANE-TA record pinning to Google's root CA would be trivial to publish) for incoming mail?
2
8
Replying to and
Wow, and google\.com isn't either. Ick. I wonder if they have some massive infrastructure problem that prevents it or if this is more ideological (possibly with underlying commercial reason) opposition to DNSSEC...
1
I can do key rotations by hand without having to worry about the Let's Encrypt renewal schedule, so using Web PKI isn't a hassle. I have no reason to host a web server on the same domain so I don't have a reason to care that the certificates aren't specific to SMTP or HTTP.
1
If MTA-STS becomes broadly deployed/expected servers could drop support for bothering with it and instead mandate TLS with Web PKI verification. It's orthogonal to using DANE for pinning a specific key or certificate. There are benefits to having this in addition to DANE like CT.