[145710] in cryptography@c2.net mail archive
Re: towards https everywhere and strict transport security (was: Has there been a change in US banking regulations recently?)
daemon@ATHENA.MIT.EDU (Jakob Schlyter)
Sun Aug 22 11:17:38 2010
From: Jakob Schlyter <jakob@kirei.se>
In-Reply-To: <C9B36A0F-3B5E-47A8-81AF-35E0D7439E94@lrw.com>
Date: Sun, 22 Aug 2010 12:56:06 +0200
Cc: cryptography@metzdowd.com
To: Jerry Leichter <leichter@lrw.com>
There are a lot of work going on in this area, including how to use =
secure DNS to associate the key that appears in a TLS server's =
certificate with the the intended domain name [1]. Adding HSTS to this =
mix does make sense and is something that is discussed, e.g. on the =
keyassure mailing list [2].
jakob
[1] http://tools.ietf.org/html/draft-hoffman-keys-linkage-from-dns-00
[2] http://www.ietf.org/mailman/listinfo/keyassure
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com