ietf-corpus

rfc-3755

Legacy Resolver Compatibility for Delegation Signer (DS)

S. Weiler
date2004-05 streamIETF areaint wgdnsext statusPROPOSED STANDARD pages9 canonicalhttps://www.rfc-editor.org/rfc/rfc3755 doi10.17487/RFC3755
As the DNS Security (DNSSEC) specifications have evolved, the syntax and semantics of the DNSSEC resource records (RRs) have changed. Many deployed nameservers understand variants of these semantics. Dangerous interactions can occur when a resolver that understands an earlier version of these semantics queries an authoritative server that understands the new delegation signer semantics, including at least one failure scenario that will cause an unsecured zone to be unresolvable. This document changes the type codes and mnemonics of the DNSSEC RRs (SIG, KEY, and NXT) to avoid those interactions. [STANDARDS-TRACK]

obsoleted by

updated by

updates