Viktor Dukhovni via Postfix-users <[email protected]> writes:
> On Sun, Aug 24, 2025 at 03:56:06AM +1000, Viktor Dukhovni wrote: > >> https://dnssec-stats.ant.isi.edu/~viktor/x3hosts.html > > By this time all certificates issued by R10–R14 and E5–E9 (as well as > all previously retired CAs) have expired, and even the ISRG X1 and ISRG > X2 roots have now been replaced. Publishing TLSA records matching the > retired CAs no longer makes sense (is unnecessary bloat in your DNS data > and a security exposure should their keys be compromised). > > Therefore, all the below DANE-TA(2) TLSA records should be dropped from > all TLSA RRsets (some Cert(0) selectors appear multiple for the same CA > because there are multiple versions of that intermediate CA's > certificate cross-signed by different issuers, ...). > > (... snip ...) > The correct sets of DANE-TA(2) TLSA records to use with Let's Encrypt > are either or both of: > > - ECDSA (YE1-YE3): > 2 1 1 6ebcefb4210b088654a38b03fea3d7d1c711b4fb1ddc363a45f9b1a4e53da01e > 2 1 1 b3fb5d00e994cddf2cc9a4eea9f806bc5727e83cc0e4299bf956f2d524fe5376 > 2 1 1 a698a20824be04e47a1a33c4fa488731be92011f23a31e900e2ca26c9c2acfce > > - RSA (YR1-YR3): > 2 1 1 2e8307068b6db620e4a39d068b5dee5d6ef5788cbb2c0b6d23ead84fcc17178c > 2 1 1 9d637b3d27a9e570d07607b9ccadb80a70915c7af72afce12841b1b1da825fd1 > 2 1 1 51aaa87d984b559ac69e929f888a022d832e089ff4dba0a412b5101bca4bc799 > > (... snip ...) Today i did updating, thanks Viktor! Sincerely, Byunghee -- ^고맙습니다 _布德天下_ 감사합니다_^))// _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
