@item I am tired that everyone provides very limited certificates trust
management capabilities, like either certificate or SPKI
@url{https://en.wikipedia.org/wiki/Certificate_pinning, pinning} with
-@url{https://en.wikipedia.org/wiki/Trust_on_first_use, TOFU}. Even my
-beloved @url{https://en.wikipedia.org/wiki/Xombrero, Xombrero} browser
-still pins only the whole certificate, but its public key would be much
-more sufficient and convenient to work with.
+@url{https://en.wikipedia.org/wiki/Trust_on_first_use, TOFU}.
@item I am tired that many clients provides very few information about
certificates and connections at all.
not friendly with TLS connections, obviously. Or use yet another
browser-specific plugin.
-@item Xombrero sometimes has problems with HTTP-based authorization.
-
@item Hardly anyone does
@url{https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities, DANE}
checks.