Comcast supporting outbound DANE Thumbnail
Internet Technologies 21 August 2017

Comcast supporting outbound DANE

By Kevin MeynellGuest AuthorNominee for the Internet Society Board of Trustees

Comcast has announced that it’s piloting outbound DANE with selected domains, as of the end of July 2017.

Back in 2015, they added TLSA records to the ‘comcast.net’ domain to allow external senders to authenticate the digital certificates presented by its MTAs, and this pilot will allow them to do the same for their traffic destined for other sites. The aim is to gain experience with this, with the plan being to eventually remove all restrictions and attempt DANE authentication for all destination domains.

DANE addresses one of the inherent weaknesses of digital certificates being issued by third-party Certificate Authorities (CAs), by allowing certificates to be cryptographically bound to DNS names. This is achieved by adding TLSA records to a DNSSEC-signed zone in the DNS, thereby allowing hosts to be validated using DNSSEC.

This is significant development from one of the major network operators that should encourage increased deployment of both DANE and DNSSEC.

And if you’re interested in deploying DANE, then you’d be well advised to read our two-part guide on how we did it in the Go6Lab.

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts

Supporting a Secure and Trustworthy Internet 6 September 2024

US Government Networks Get a Security Boost: White House Roadmap Tackles Routing Vulnerabilities

The White House's Roadmap to Enhancing Routing Security is an important step toward strengthening routing security in the United...

Supporting a Secure and Trustworthy Internet 14 May 2024

The US Makes a Big Step Toward Better Routing Security

The US Department of Commerce began implementing better routing security practices—a step in the right direction for wider MANRS...

Securing Border Gateway Protocol (BGP) 18 April 2024

The US FCC Signals a Dangerous New Course on BGP Security

The US Federal Communications Commission recently released a draft Declaratory Ruling and Order in the Open Internet Proceeding. However,...