Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wishlist: TLSA/DANE support #167

Open
croessner opened this issue Dec 27, 2014 · 0 comments
Open

Wishlist: TLSA/DANE support #167

croessner opened this issue Dec 27, 2014 · 0 comments

Comments

@croessner
Copy link

It would be really nice to have TLSA/DANE (RFC 6698) support in tlsdate. As tlsdate is connecting to a remote side, it would be nice to have some authentication mechanism to protect against DNS spoofing. Because tlsdate is doing https, TLSA/DANE is already a "good" solution.

If tlsdate does DANE, it can refuse to set the local time, if the remote (foreign) server was not authenticated with a valid TLSA fingerprint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant