https://www.infoblox.com/dns-security-resource-center/dns-security-faq/what-is-dane/
A single trusted CA can undermine the security of the entire system, because, by design, any CA can issue certificates for any domain name, such as www.infoblox.com, and that particular illegitimate c