[one-users] Sunstone noVNC with WSS support
Stefan Kooman
stefan at bit.nl
Tue Mar 11 09:07:47 PDT 2014
Quoting Valentin Bud (valentin.bud at gmail.com):
>
> I totally agree with you about the user experience and for it is worth
> investing
> a few dollars. I guess I am just frustrated that TLS fails to provide peer
> to peer
> trust.
So I guess it's time (for you) to deploy DANE [1,2]. You do need to have
DNSSEC enabled for your domain ... and still have to trust the (root)
dns servers ... but that's already a big improvement if you ask me.
Especially if you operate your own dnsservers and have control over the
signing process.
[1]: https://tools.ietf.org/html/rfc6698
[2]: http://www.internetsociety.org/deploy360/blog/2013/12/want-to-quickly-create-a-tlsa-record-for-dane-dnssec/
--
| BIT BV http://www.bit.nl/ Kamer van Koophandel 09090351
| GPG: 0xD14839C6 +31 318 648 688 / info at bit.nl
More information about the Users
mailing list