> provide the public keys to my clients
How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?
How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?
The role CAs play is to be a trusted identity verifier so we don't have to have millions of people driving around to do key exchanges in person.
I think the idea of a CA is good but it should be distributed somehow
CAs are quite distributed already. You probably have a couple dozen or even a hundred different root CAs installed right now, and you can install whatever ones you like if necessary.
All caches are just functionally useless layers..., so that's that.
You can give out the same claim over DNS directly without any extra third party involvement in the form of CA.