Moving DNSSEC Lookaside Validation (DLV) to Historic Status
updates
Extracted elements (8)
DLV was introduced when the root zone and many TLDs were unsigned, allowing trust anchors to be published outside the normal DNS delegation chain. With the root zone signed in 2010 and 1389 of 1531 TLDs securely delegated as of May 2019, DLV has served its purpose.
Keeping DLV has concrete disadvantages: it reduces pressure on parent zones and registrars to adopt DNSSEC, complicates validation code, and only two validators (BIND 9 and Unbound) ever implemented it. The sole well-known registry, dlv.isc.org, was deprecated on September 30, 2017.
RFC 8198 ('Aggressive Use of DNSSEC-Validated Cache') references RFC 5074 only because aggressive negative caching was first proposed there; moving RFC 5074 to Historic does not affect RFC 8198's normative content.
Moving RFC 4431 and RFC 5074 to Historic status signals that the DLV resource record and DLV mechanism SHOULD NOT be implemented or deployed.
RFC 6698 is updated to exclude the DLV resource record from DNSSEC certificates; DLV RRs no longer form part of the signing chain binding identity to key.
RFC 6840 is updated to exclude DLV registries from trust anchor selection; validators MUST NOT consider DLV registries when choosing among trust anchors from different sources.
IANA has updated the annotation of the DLV RR type (code 32769) to 'Obsolete' in the 'Domain Name System (DNS) Parameters' registry.
Once DLV is retired, zones that relied on DLV for validation will be treated as insecure. The practical risk is low because no well-known DLV registry currently exists.