Remix.run Logo
UltraSane 4 hours ago

And route53 makes DNSSEC very easy to enable so all the DNS data is cryptographic signed. This makes putting public keys and certificates in DNS much more sensible.

cbm-vic-20 3 hours ago | parent [-]

I dug into the DNSSEC rabbit hole a few weeks ago and got drawn into the fascinating root key signing ceremony.

https://www.iana.org/dnssec/ceremonies/62

ecliptik 2 hours ago | parent [-]

I knew of GPG key signing parties, but never anything at this scale or impact. Might try booting the "Signing Computer Operating System Image Release coen-2.0.1" ISO in a VM and checking it out.

UltraSane 2 hours ago | parent [-]

It really is something to behold. When you start storing FIPS 140-2 Level 4 HSMs offline inside safes you know things are serious.