Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNSSEC and DNS-01 challenges might do the trick at the cost of significant effort, provided LE could be directed to check, similar to the way MTA-STS works.


Let’s Encrypt has been doing DNSSEC validation for years. DNSSEC could have prevented the jabber.ru MITM attack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: