> An attacker should not gain the ability to
> persistently issue certificates because they
> have one-time access to DNS.
They wouldn't. As soon as the owner of the domain removes the TXT entry that ability would be gone.
They wouldn't. As soon as the owner of the domain removes the TXT entry that ability would be gone.
(Which in general would be a good practise anyway, because many services do use domain validation processes similar to what you propose)