2019-10-15 21:17:24
On 10/15/19 9:36 PM, Hector Santos wrote:

The technical security aspect of encryption is no longer good enough 
-- certs now have to be CA-signed now.

Certs that weren't signed by a trusted party were never worth anything 
anyway, unless maybe you manually pinned them.

We were talking about bootstrapping DNSSEC.  Certs?  What are those?

