Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check for TLSA record (DANE) #179

Open
J0WI opened this issue Jan 17, 2019 · 0 comments
Open

Check for TLSA record (DANE) #179

J0WI opened this issue Jan 17, 2019 · 0 comments

Comments

@J0WI
Copy link

J0WI commented Jan 17, 2019

DANE combines TLS with DNSSEC (#30) and so it provides the highest level of trust. The fingerprint is stored in a TLSA record.
There are already some test sites for this (e.g. https://www.internet.nl/), so this could also be integrated as a third-party test.

Here are some examples:

$ dig _443._tcp.torproject.org TLSA +short
3 1 1 1599B2352EE910499C0DA1A104575935477C5765CCD10D81F43B50AC 30034C76
$ dig _443._tcp.debian.org TLSA +short
3 1 1 5F33491E2B2D267F7BFF096AD0DCB4AE5A22C0BE19DB0AB6728BED94 2F0719FC
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant