Why are we still using the CA model? (Re: Microsoft deems all DigiNotar certificates untrustworthy, releases updates)

Martin Millnert millnert at gmail.com
Mon Sep 12 15:17:55 UTC 2011

On Mon, Sep 12, 2011 at 5:09 PM, Michael Thomas <mike at mtcc.com> wrote:
> And how long would it be before browsers allowed self-signed-but-ok'ed-using-dnssec-protected-cert-hashes?

As previously mentioned, Chrome >= v14 already does.


More information about the NANOG mailing list