Re: confidence in CA



Anne & Lynn Wheeler wrote:

one could even imagine a highly optimized SSL variation where any
public key and crypto-opts are piggy-backed on the same domain name
infrastructure response that provided the domain name to ip-address
mapping (totally eliminating the majority of existing SSL setup
protocol chatter)

The more flexible variant of this is called OSCP.
.