[one-users] Sunstone noVNC with WSS support

Stefan Kooman stefan at bit.nl
Tue Mar 11 09:07:47 PDT 2014

Quoting Valentin Bud (valentin.bud at gmail.com):
> I totally agree with you about the user experience and for it is worth
> investing
> a few dollars. I guess I am just frustrated that TLS fails to provide peer
> to peer
> trust.

So I guess it's time (for you) to deploy DANE [1,2]. You do need to have
DNSSEC enabled for your domain ... and still have to trust the (root)
dns servers  ... but that's already a big improvement if you ask me.
Especially if you operate your own dnsservers and have control over the
signing process.

[1]: https://tools.ietf.org/html/rfc6698
[2]: http://www.internetsociety.org/deploy360/blog/2013/12/want-to-quickly-create-a-tlsa-record-for-dane-dnssec/

| BIT BV  http://www.bit.nl/        Kamer van Koophandel 09090351
| GPG: 0xD14839C6                   +31 318 648 688 / info at bit.nl

More information about the Users mailing list