MelindaShore / dnssec-serialization

Internet draft(s) proposing a standard for serialization and transport of dnssec/dane validation chains
0 stars 1 forks source link

Need to add text clarifying where the serialization chain ends #2

Open MelindaShore opened 9 years ago

MelindaShore commented 9 years ago

From Shumon: We might want to be clearer about whether the serialization chain ends in the TLS server's domain name or in a TLSA record corresponding to the server's TLS certificate. For DANE authentication, the latter would be needed, but it may make sense to have the former (also), so that the client can authenticate the server's DNSSEC name to IP address mapping.

MelindaShore commented 9 years ago

Melinda: We might want to think about having some text describing dnssec use (authenticating the domain name) and separate text describing dane use .