SSL Certificate Authorities Explore New Secuirty Options #rsac | Internet News

SSL Certificate Authorities Explore New Secuirty Options #rsac

Mar 1, 2013
1 minute read

SSL CAAt the RSA Security conference this week, a panel of CAs and researchers discussed ideas that could help shore up the system of awarding SSL certificates.

DANE Leverages DNS

Yngve Pettersen, a software developer and security specialist for TLS Prober Labs, mentioned an approach known as DANE (DNS-based Authentication of Named Entities). DANE is defined by the IETF (Internet Engineering Task Force) 6698 RFC and leverages the DNS to validate the integrity of an SSL certificate. More specifically, DANE requires that DNSSEC is implemented on a DNS server, providing an additional layer of integrity to domain name information.

“DANE allows the owner of a domain to signal which site certificate can be used, which CAs can be used and which public keys can be used for a given host in a domain,” Pettersen said.

However, one issue with DANE that Pettersen highlighted is the fact that it’s not clear how effective certificate revocation would be handled.

Read the full story at eSecurityPlanet:
RSA 2013: SSL Certificate Security in the Crosshairs

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.