Now that ECH is happening, which implies SVCB... can we pleeeeease get DANE/TLSA and in-band DNSSEC in TLS?
In-band DNSSEC addresses the complaints from browsers about DNS queries, and SVCB could be a perfect solution to the downgrade issue with in-band DNSSEC.
Or better yet... just replace TLSA with an SVCB SvcParam, drastically simplifying the whole thing.
I have little hope, seeing as everyone seems to have gotten burned last time. A real shame, since the argument may as well be moot now.