there are integrity and vulnerability issues with the domain name infrastructure
these integrity and vulnerability issues can result in various kinds of "take-over" exploits. the SSL domain name certificates are designed to detect ip-address take-over exploits (not prevent them) ... and do nothing to detect other kinds of take-over exploits. not detecting an exploit can lead to fraudulent transactions resulting in a financial impact detecting an exploit will effectively degenerate to a denial of service exploit integrity and vulnerability issues with the domain name infrastructure can result in various kinds of denial of service exploits denail of service exploits of the domain name infrastructure can result in significant financial and economic impact, possibly on par with fraudulent transactions. just detecting an exploit and changing it from a fraudulent transaction exploit to denial of service exploit would still represent a signficant financial and economic impact it is possible to take a baby step for real-time distribution of public keys by the domain name infrastructure .... compared to the current infrastructure this baby step can compensate for existing domain name infrastructure integrity issues by having the public key signed (as opposed to distributing naked public keys) the current SSL domain name operation is a certificate manufactoring infrastructure w/o the certificate management characteristics necessary for a PKI the baby step distribution of real time public keys can provide effectively the characteristic of management of public keys ... by deciding whether or not to distribute the public key the baby step is consistent with the certification authority business proposal for addressing domain name take-over exploits (registering public keys with the registering of the domain name). the baby step doesn't address the elimination of denial of service exploits (any more than the current SSL domain name certificates do). with the baby step there can still be denial of service attacks on the domain name infrastructure the baby step of adding public key distribution to the domain name infrastructure provides public key management capability significantly more efficiently than either distributing CRLs to every potential client in the world and/or having clients execute OCSP transaction. the baby step is consistent with some future real time distribution of "naked" public keys (w/o the signing envelope) at some future time when the integrity and vulnerability issues of the domain name infrastructure have been sufficiently addressed. there are significant financial and economic justification for addressing these integrity and vulnerability issues just based on the impact of denial of service exploits. neither the existing ssl domain name certificate infrastructure nor the baby step prevent ip-address take-over exploits and both just turn an ip-address take-over exploit into a denial of service exploit. neither the existing ssl domain name certificate infrastructure nor the baby step prevent denial of service exploits the baby step with real time distribution of public keys (whether enveloped with signature for additional integrity or "naked") is consistent with the certification authority business proposal for improving the integrity of the domain name infrastructure by addressing domain name take over exploits by registering public keys in the domain name database entry.
