The rationale behind DANE is that given that the DNS administrator for a domain name is
authorized to provide identifying information about his jurisdiction zone, he should be allowed
to make an authoritative binding between the domain name and a certifi cate that might be used
by a host at that domain name. According to this line of thinking, the proper place to hold this
information is the DNS database, securing the binding with DNSSEC.