▲ | fpoling 3 days ago | |||||||
That does not work as DNS is insecure. DNSSEC is not there and may never will. | ||||||||
▲ | ryandv 3 days ago | parent | next [-] | |||||||
But this is already basically how Let's Encrypt challenges certificate applicants over ACME DNS01 [0]. I would be more concerned about the number of certificates that would need to be issued and maintained over their lifecycle - which now scales with the number of unique clients challenging your server (or maybe I misunderstand, and maybe there aren't even certificates any more in this scheme). Not to mention the difficulties of assuring reasonable DNS response times and fresh, up-to-date results when querying a global eventually consistent database with multiple levels of caching... [0] https://letsencrypt.org/docs/challenge-types/#dns-01-challen... | ||||||||
| ||||||||
▲ | detaro 3 days ago | parent | prev [-] | |||||||
And would be replacing the CA PKI with an even more centralized PKI. |