DANE / TLSA

👥kind protocolusage identitynamingenc contenttopology federatedentity federatedid pubkey
started
2012
by
Paul Hoffman, Jakob Schlyter, IETF
homepage
https://www.rfc-editor.org/rfc/rfc6698
wikipedia
https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

DNS-based Authentication of Named Entities (RFC 6698). Publish TLS certificate fingerprints in DNS records signed by DNSSEC; an alternative to the PKI cert authority model. Notably used by SMTP MTA-STS replacement and some PGP keyservers.

Inspired by

Uses