Join Nostr
2026-03-26 13:13:56 UTC
in reply to

Mae on Nostr: Uninformed reply, I havent read the RFCI think if this was only used for fallback ...

Uninformed reply, I havent read the RFCI think if this was only used for fallback this might be ok, but I'm worried there are gonna be cases where this is the only option, and I don't think it's a good idea to force all http clients to also do DNS resolution
Also doesn't dnssec have a completely different model compared to the "standard" root ca infra? I think security people wouldn't like that