ietf-corpus

rfc-8945

Secret Key Transaction Authentication for DNS (TSIG)

F. Dupont, S. Morris, P. Vixie, D. Eastlake 3rd, O. Gudmundsson, B. Wellington
date2020-11 streamIETF areaops wgdnsop statusINTERNET STANDARD pages22 canonicalhttps://www.rfc-editor.org/rfc/rfc8945 doi10.17487/RFC8945 errataview
This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server. No recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism. This document obsoletes RFCs 2845 and 4635.

obsoletes

also