Proposal: extend bip70 with OpenAlias



Summary:

In response to a query, Russ explained that DNSSEC is used to sign the zones and only the domain owner would be able to issue certificates for a zone or corresponding email address. This means that there would be only one certificate authority (CA) per domain. However, if someone else manages to hack into your email account and obtains a certificate in your name, it would be difficult for you to know about it because they would use a different CA.


Updated on: 2023-06-10T02:37:02.294527+00:00