RFC 08032022
***** RFC08032022 ***** The TLS 1.3 is not always correctly implemented on the DNS Public Key Infrastructure (PKI). We can replace it by the state-of-the-art Wireguard. There are several aspects to consider in the DNS: 1. The concentration of risk in a PKI 2. The generation of domain names certificates 3. The storage of domain names certificates 4. The access to domain names certificates 5. The DNS requests and answers 6. The access to the Web ressources 7. The DNS servers information 1.The DNS PKI has several levels and concentrates risk on very few root Certification Authorities (CAs). Also, it is said that some root certificates private keys have leaked. We shall use only one level to reduce risk. Indeed, absolute root CAs shall be seen as the top of the DNS PKI pyramid. https://cpl.thalesgroup.com/faq/public-key-infrastructure-pki/what-certification-authority-or-root-private-key-theft Also, it appears clearly that websites providing information about compromising electromagnet...