Could you kindly link to relevant threads / RFCs / orgs / undertakings currently working on that, please?
Could you kindly link to relevant threads / RFCs / orgs / undertakings currently working on that, please?
3 -- Certificate usage 3 is used to specify a certificate, or the public key of such a certificate, that MUST match the end entity certificate given by the server in TLS. This certificate usage is sometimes referred to as "domain-issued certificate" because it allows for a domain name administrator to issue certificates for a domain without involving a third-party CA.
Then again, I was responding to the question about an RFC or other standard, not whether it was feasible today. ;-)
I think using DNS over HTTPS in conjunction with signing the response is going to be more viable since you don't have 200 ways a middle box will break it.
I've heard of blockchain based ideas as well but I'll leave that to your google-fu