Viktor Dukhovni via Postfix-users <[email protected]> writes:

> On Sun, Aug 24, 2025 at 03:56:06AM +1000, Viktor Dukhovni wrote:
>
>>     https://dnssec-stats.ant.isi.edu/~viktor/x3hosts.html
>
> By this time all certificates issued by R10–R14 and E5–E9 (as well as
> all previously retired CAs) have expired, and even the ISRG X1 and ISRG
> X2 roots have now been replaced.  Publishing TLSA records matching the
> retired CAs no longer makes sense (is unnecessary bloat in your DNS data
> and a security exposure should their keys be compromised).
>
> Therefore, all the below DANE-TA(2) TLSA records should be dropped from
> all TLSA RRsets (some Cert(0) selectors appear multiple for the same CA
> because there are multiple versions of that intermediate CA's
> certificate cross-signed by different issuers, ...).
>
>   (... snip ...)
> The correct sets of DANE-TA(2) TLSA records to use with Let's Encrypt
> are either or both of:
>
>     - ECDSA (YE1-YE3):
>       2 1 1 6ebcefb4210b088654a38b03fea3d7d1c711b4fb1ddc363a45f9b1a4e53da01e
>       2 1 1 b3fb5d00e994cddf2cc9a4eea9f806bc5727e83cc0e4299bf956f2d524fe5376
>       2 1 1 a698a20824be04e47a1a33c4fa488731be92011f23a31e900e2ca26c9c2acfce
>
>     - RSA (YR1-YR3):
>      2 1 1 2e8307068b6db620e4a39d068b5dee5d6ef5788cbb2c0b6d23ead84fcc17178c
>      2 1 1 9d637b3d27a9e570d07607b9ccadb80a70915c7af72afce12841b1b1da825fd1
>      2 1 1 51aaa87d984b559ac69e929f888a022d832e089ff4dba0a412b5101bca4bc799
>
> (... snip ...)

Today i did updating, thanks Viktor!


Sincerely, Byunghee

-- 
^고맙습니다 _布德天下_ 감사합니다_^))//
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to