<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Web SSL Certificates verified by DNSSEC-protected DNS records (DANE TLSA)]]></title><description><![CDATA[<p dir="auto">If I visit a https website which uses a self signed certificate and has valid TLSA Records protected by DNSSEC according to RFC-6698 and RFC-7218 (e.g. <a href="https://www.udin.ch" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.udin.ch</a>), Opera comes up with the usual warning message because it validates against Trusted Root CAs only.</p>
<p dir="auto">Opera should prefer and honor DNSSEC-validated TLSA before falling back to "classic" Root CA TLS verification. This would enable everyone to use their own self-signed certificates and give a real motivation to implement DNSSEC.</p>
]]></description><link>https://forums.opera.com/topic/11681/web-ssl-certificates-verified-by-dnssec-protected-dns-records-dane-tlsa</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 21:12:02 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/11681.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2015 10:39:53 GMT</pubDate><ttl>60</ttl></channel></rss>