Comment Re: Does it make sense to trust any govt key? (Score 0) 112
Actually, there are name constraints that would allow you to sign for yourself if you could anchor your own CA to the trust chain. Weâ(TM)re closer than many think.
In order for that to work though, the name constraint would need to be marked critical (refuse trust chain if not supported), and itâ(TM)s mostly just Apple that doesnâ(TM)t support it.
If Apple fixes that, and Letâ(TM)s Encrypt (for example) would let you anchor from them, things could move in that direction.
Personally Iâ(TM)d have liked to see these things integrated into DNSSEC as well.