| ▲ | altairprime 20 hours ago | |
I’d be totally onboard with TLD-locking them to legal jurisdictions they’re comfortable being bound to, except that this would underserve a great deal of the Internet. Don’t really have a great solution yet, either. Perhaps as each TLD operates DNSSEC they could sign authorized issuers by publishing TLD CAA records, which would create some legal zone accountability that’s lacking today (and give the EU a lever by which to cut off U.S. registrars from their zones). But I have no idea how to effect any of that change, and Let’s Encrypt is truly screwed in this model as a worldwide entity. The endgame might actually be “to operate a domain registrar you must be a PKI”, which would ravage the segment and probably permanently kill off Namecheap (one can dream). So, yeah, I agree: I think instead we absolutely will see fragmentation, at both software (PKI) and, eventually, hardline levels, rather than see domain registrars and PKI issuers be forcibly merged by policy. | ||
| ▲ | inigyou 10 hours ago | parent [-] | |
We should let each country specify trusted CAs the way they specify their DNS signing keys. Or we should just implement DANE already and then the same key serves both purposes and we can delete WebPKI from the world. | ||