dns is a non-issue if the rest of ssl is working.
dns is irrelevant if it isn't.

Except when SSL has chinks in its armor.  Like incidents of
certificate authorities being convinced to give out certs for
domains that don't belong to the requestor.  Or bugs in SSL
cert validation that compares names only up to the NUL character
and certificate authorities willing to make CERTs with NULs
in the cert name. Or certificate authorities giving out unqalified
"local" certificates that can be repurposed as non-local certs.
Or simply the fact that the majority of the
SSL using population has been trained to disreguard SSL mismatches
by clicking through any dialog box that appears while browsing.

At any rate, it would be nice having a certificate system that
was more closely tied to the DNS heirarchy...

russ

Tim Newsham | www.thenewsh.com/~newsham | thenewsh.blogspot.com

Reply via email to