Hi Cynthia & all,
On Tue, 21 Jul 2026, 'Cynthia Revström' via [email protected]
wrote:
While I will happily acknowledge that I don't think there's really any
good reason to do this, I also haven't seen any proper arguments
against it.
The arguments against it feel like they mostly come from a place of
people just not liking it for whatever reason rather than any real
technical or other objective reason.
Speaking for myself, I do not like it because, you said yourself, "I don't
think there's really any good reason to do this.". This suggests that
anyone actually using/depending on these certificates (at the time there
were less than a handful of valid, publicly trusted rdns certificates and
none in any way that demonstrated what we might be overlooking when it
comes to good reasons for using those) would be motivated by goals not
aligned with those of WebPKI (as generally seen by Browsers, at least),
and create future roadblocks or impediments when the WebPKI needs to move
to address a threat or an issue but thereby would come into conflict with
the purpose of these certificates.
...Like POS terminals & MD5 at the time.
This logic applies generally to all of .arpa, of course. There has been
some pushback from the general direction of IETF participants, who had
potential future use cases under other parts of the .arpa tree in mind.
IIRC this was never resolved, instead we decided to at least cover rDNS.
In that spirit, e164.arpa should be added to the list, I'd think, and if
we can identify more parts of the tree for which this is also true, then
they should be added as well.
Tobi
--
You received this message because you are subscribed to the Google Groups
"[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion visit
https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/dfb9055a-8ed9-4628-9b48-a27ba1523542%40opera.com.