Conversation

*sigh* TIL there is a domain tlsa[.]is whose whole purpose is letting you write cursed stuff like _25._tcp.mail IN CNAME _letsencrypt.tlsa.is.
1
2
We get unbelievably perfect tools for establishing trust of keys without gratuitous third party authorities and yet some admins can't be bothered to manage their own private key identity and instead outsource through 3+ gratuitous third parties.
1
Replying to
Let's Encrypt is also primarily providing certificates via unauthenticated HTTP(S) verification of domain control. It's going to become possible to restrict it to only DNS-based verification via CAA but for the time being either can always be used. It's more than a trusted party.
2
1