doc: DANE: don't claim TA can be elided from chain
authorPhil Pennock <pdp@exim.org>
Fri, 13 Jul 2018 16:24:26 +0000 (12:24 -0400)
committerPhil Pennock <pdp@exim.org>
Fri, 13 Jul 2018 16:24:26 +0000 (12:24 -0400)
commit97cfe5fe573cebfb1a98079e9d130c83755bb210
treec4d89112dfd899c212f70ee8a268ca16ff988740
parent9122c6523b5c178a0ab4e28115e15179b1e6dea6
doc: DANE: don't claim TA can be elided from chain

While technically an implementation can choose to use a public TA from
DNS or elsewhere to populate a missing TA from the chain, that creates
interoperability issues and the OpenSSL integration code, at least,
doesn't support that and after a bit of work drilling through layers of
abstraction, I've not figured out what GnuTLS does and I've decided I
don't care.

So I'm heeding Viktor's advice and changing the docs to just say to
publish the TA in the chain sent by the server.
doc/doc-docbook/spec.xfpt