> In these conditions, what is the point of securing the DNS look-up? The
> end-to-end verification of the certificate will validate it.

Exactly. This is also the reason why we don't have an "ARPSEC" protocol.

Or perhaps we do, but is about as exciting as DNSSEC. I wrote about this on
http://ds9a.nl/secure-dns.html .


