os3sec / Extended-DNSSEC-Validator

Firefox add-on for verification of x509 certificates using DNSSEC as bootstrap mechanism
http://os3sec.org
15 stars 9 forks source link

Change TLSA lookup #10

Closed plange closed 13 years ago

plange commented 13 years ago

Re: dealing with multiple TLS based services on one host / port number associations

Consensus has been reached on the placement of the TLSA record: http://www.ietf.org/mail-archive/web/keyassure/current/msg01716.html (not on the label itself, where we look it up now)

Chances are it will be option #2 from http://www.ietf.org/mail-archive/web/keyassure/current/msg01631.html

dannygroenewegen commented 13 years ago

Version 0.5 complies with the specifications of draft-11: _443._tcp.os3sec.org