| ▲ | UltraSane 4 hours ago |
| And route53 makes DNSSEC very easy to enable so all the DNS data is cryptographic signed. This makes putting public keys and certificates in DNS much more sensible. |
|
| ▲ | cbm-vic-20 3 hours ago | parent [-] |
| I dug into the DNSSEC rabbit hole a few weeks ago and got drawn into the fascinating root key signing ceremony. https://www.iana.org/dnssec/ceremonies/62 |
| |
| ▲ | ecliptik 2 hours ago | parent [-] | | I knew of GPG key signing parties, but never anything at this scale or impact. Might try booting the "Signing Computer Operating System Image Release coen-2.0.1" ISO in a VM and checking it out. | | |
| ▲ | UltraSane 2 hours ago | parent [-] | | It really is something to behold. When you start storing FIPS 140-2 Level 4 HSMs offline inside safes you know things are serious. |
|
|