ietf-corpus

rfc-8749

Moving DNSSEC Lookaside Validation (DLV) to Historic Status

W. Mekking, D. Mahoney
date2020-03 streamIETF areaops wgdnsop statusPROPOSED STANDARD pages6 canonicalhttps://www.rfc-editor.org/rfc/rfc8749 doi10.17487/RFC8749
This document retires DNSSEC Lookaside Validation (DLV) and reclassifies RFCs 4431 and 5074 as Historic. Furthermore, this document updates RFC 6698 by excluding the DLV resource record from certificates and updates RFC 6840 by excluding the DLV registries from the trust anchor selection.

updates

Extracted elements (8)

design-rationale §1

DLV was introduced when the root zone and many TLDs were unsigned, allowing trust anchors to be published outside the normal DNS delegation chain. With the root zone signed in 2010 and 1389 of 1531 TLDs securely delegated as of May 2019, DLV has served its purpose.

dns, security

design-rationale §3

Keeping DLV has concrete disadvantages: it reduces pressure on parent zones and registrars to adopt DNSSEC, complicates validation code, and only two validators (BIND 9 and Unbound) ever implemented it. The sole well-known registry, dlv.isc.org, was deprecated on September 30, 2017.

dns, security

interoperability-note §4.1.2.3

RFC 8198 ('Aggressive Use of DNSSEC-Validated Cache') references RFC 5074 only because aggressive negative caching was first proposed there; moving RFC 5074 to Historic does not affect RFC 8198's normative content.

dns

normative-requirement §4 SHOULD NOT

Moving RFC 4431 and RFC 5074 to Historic status signals that the DLV resource record and DLV mechanism SHOULD NOT be implemented or deployed.

dns, security

normative-requirement §4.1.2.1 MUST NOT

RFC 6698 is updated to exclude the DLV resource record from DNSSEC certificates; DLV RRs no longer form part of the signing chain binding identity to key.

dns, pkix, security

normative-requirement §4.1.2.2 MUST NOT

RFC 6840 is updated to exclude DLV registries from trust anchor selection; validators MUST NOT consider DLV registries when choosing among trust anchors from different sources.

dns, security

registry §5

IANA has updated the annotation of the DLV RR type (code 32769) to 'Obsolete' in the 'Domain Name System (DNS) Parameters' registry.

dns, registry

security-consideration §6

Once DLV is retired, zones that relied on DLV for validation will be treated as insecure. The practical risk is low because no well-known DLV registry currently exists.

dns, security