> Who is right?

Both :-)

Programmers may not have a version of OpenSSL or GnuTLS recent enough,
or they may use another TLS library, or the binding to GnuTLS/OpenSSL
they use for their favorite programming language may not expose DANE
validation yet.

