For ssh that doesn't really apply as clearly though.
For ssh that doesn't really apply as clearly though.
Do all CAs implement multi-prespective validation these days? Let's Encrypt implemented that only in 2020 and they believed they were the first ones:
https://letsencrypt.org/2020/02/19/multi-perspective-validat...
https://datatracker.ietf.org/doc/html/draft-zhang-trans-ct-d...
https://www.huque.com/2014/07/30/dnssec-key-trans.html
https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-deleg...
DNS root key compromise breaks the entire system until it is replaced.
Not seeing a huge difference.
It is not possible to revoke the DNS root, and there are no widely deployed alternatives. The incentive to do the right thing isn't as hard: it's just "good" guys doing the right stuff. If something wrong happens, where will you go ? Nowhere else.
In contrast, there is no unique "root CA" that can fail.
Do you think that DNS-based proof of ownership is not something that CAs would use for SSH certification?