Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
What you are proposing sounds like DANE with TLSA and DNSSec. Great idea but most CC TLDs are still using 1024 RSA ZSKs. Right now PQ DNSSEC is very uncertain. PQ DNSSEC will likely take about 5 more years or so to standardise. And thats too late for companies like Google and Cloudlfare which want to go PQ Crypto by 2029.
No, I'm proposing that TLD can handle issuance themselves since they technically have 100% control over domains under their TLDs anyways. I think this might be important when we look at a combination of short (and getting shorter) lifetimes for end-user certificates and increasing volatility of the world (cyberattacks, sabotage and war). It would be desirable for ccTLD's specifically to be able to maintain certificate issuance even though the country was virtually or physically isolated from the rest of the world. (Which DANTE could/would have mitigated but is not my proposal here)
It's almost like they could put their CA's public key into the dns, and the sub-zones could carry signatures over their own keys, to make dns secure. you could call it something like "dnssecure".
phillipseamore · · focus · HN ↗
vg · · focus · HN ↗
phillipseamore · · focus · HN ↗
sneak · · focus · HN ↗