ietf-corpus

rfc-8145

Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)

D. Wessels, W. Kumari, P. Hoffman
date2017-04 streamIETF areaops wgdnsop statusPROPOSED STANDARD pages13 canonicalhttps://www.rfc-editor.org/rfc/rfc8145 doi10.17487/RFC8145
The DNS Security Extensions (DNSSEC) were developed to provide origin authentication and integrity protection for DNS data by using digital signatures. These digital signatures can be verified by building a chain of trust starting from a trust anchor and proceeding down to a particular node in the DNS. This document specifies two different ways for validating resolvers to signal to a server which keys are referenced in their chain of trust. The data from such signaling allow zone administrators to monitor the progress of rollovers in a DNSSEC-signed zone.

updated by