Internet Technologies 2 December 2013

Afnic Publishes Issue Paper: “Securing Internet Communications End-to-end Using DANE Protocol”

By Dan YorkSenior Director, Online Trust and Safety

Afnic paper on DANELast week, the great folks over at Afnic released an outstanding issue paper about how the DANE protocol and DNSSEC can bring a higher level of trust and security to Internet-based communications.  The issue paper, “Securing End-to-end Internet communications using DANE protocol“, is available in PDF (direct link) and walks through how DANE can be used to increase the security used in TLS/SSL certificates (PKIX).  The document describes the problems associated with the current world of certificates and then explains how DANE can make the situation more secure.

Readers of this Deploy360 site will know that we’ve produced similar types of documents ourselves, but not in an “issue paper” form that can be distributed.  The Afnic folks have done a great job with this and I like the graphics they are using.

As they note on the final page, DANE is for much more than web browsing – and in fact the major implementations we’re seeing right now are in other services like email and XMPP (Jabber). The browser vendors have so far not seen enough requests (we are told) to look at including DANE in their browsers.

Hopefully this document from Afnic will help people further understand the very real value DANE can bring in ensuring that you are using the correct TLS/SSL certificate when you are connecting to a web site.

Kudos to the Afnic team for creating this document – and I encourage everyone to share this document widely! (Thanks!)

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts

Open Internet Standards 21 May 2026

On Global Accessibility Awareness Day, An Internet for Everyone Must Include Everyone 

Today, 21 May, marks the 15th Global Accessibility Awareness Day (GAAD)–a day dedicated to getting everyone talking, thinking, and learning about...

Internet Policy 3 April 2026

DNS Blocking: Mind the Unintended Consequences

As DNS blocking mandates multiply, so do concerns about security, the openness of the Internet, and fragmentation.

Rebuilding Trust 16 January 2025

Today’s US Executive Order is a Serious Win for Cybersecurity

The United States government is taking a major leap forward for cybersecurity. The newly released Executive Order on Strengthening and...