Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Melinda Shore
On 7/19/15 11:49 AM, Viktor Dukhovni wrote: > My reading of the draft is that it is primary aimed at making DANE > practical for HTTPS, where last-mile considerations on the client > end are a significant part of the adoption barrier. > > For HTTP, MX and SRV records are out of scope. Clients th

Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Viktor Dukhovni
On Sun, Jul 19, 2015 at 08:18:18PM +0200, Daniel Kahn Gillmor wrote: > On Wed 2015-07-01 05:58:20 +0200, Viktor Dukhovni wrote: > > Instead, there would need to be in various cases: > > > > * A validated chain of CNAMEs (possibly synthesized via validated > > DNAME RRs) leading from the

Re: [TLS] draft-shore-tls-dnssec-chain-extension-00

2015-07-19 Thread Daniel Kahn Gillmor
Thanks for this draft, i'm definitely interested in seeing it push forward. On Wed 2015-07-01 05:58:20 +0200, Viktor Dukhovni wrote: > Instead, there would need to be in various cases: > > * A validated chain of CNAMEs (possibly synthesized via validated > DNAME RRs) leading from the cli