Opportunistic Security for HTTP
greenbytes.de
greenbytes.de
Could you explain this in more detail?
If they say I own Google.com, I own it in every possible way, and I should be able to generate certificates for it. That's regardless of whether we use a CA model or a DNS-delegated one such as DANE.
I would be perfectly fine with a model where we store certificates directly in WHOIS, but that would be slower and less practical that just using DNSSEC, which is already deployed.
I guess it may be hard to get everybody's trust if you're running a CA as a side business.
I would love to have certificates for all of my domains, but it simply isn't worth it to me for the 40 - 50 hits a month I get on those properties to pay for a cert, or go through the hassle of StartSSL and worry about having to pay if the next Heartbleed happens.
"The server certificate, if one is proffered by the alternative service, is not necessarily checked for validity, expiration, issuance by a trusted certificate authority or matched against the name in the URI."
In other words, the certificate presented is merely used to secure the connection against a passive attacker.