You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"Great care must be taken (with Certificate usages other than
DANE-EE(3)) to ensure that the TLSA record matches a certificate
that is actually part of the server's chain and not just some random
unrelated certificate that happens to be present in the server
certificate message. Many implementors fail to check this."
The text was updated successfully, but these errors were encountered:
While true, I'm inclined to say that the DANE certificate verification details should be discussed (and are already are discussed) elsewhere, like the DANE OPS doc (in IESG review) that Viktor is an author of. If needed, we could add a pointer to that document.
From Viktor:
"Great care must be taken (with Certificate usages other than
DANE-EE(3)) to ensure that the TLSA record matches a certificate
that is actually part of the server's chain and not just some random
unrelated certificate that happens to be present in the server
certificate message. Many implementors fail to check this."
The text was updated successfully, but these errors were encountered: