[Cryptech Tech] Some problems with the repo access

Jakob Schlyter jakob at kirei.se
Sat Feb 15 19:06:16 UTC 2014


On 15 feb 2014, at 16:55, Rob Austein <sra at hactrn.net> wrote:

> This assumes that one considers being independent of the full PKIX
> path validation to be a feature.  I'm not convinced.

Ah, if you want to require both classic PKIX and DANE, you should do TLSA {0,1} x y, not TLSA {1,2} x y.

	jakob




More information about the Tech mailing list