IETF RFC 8078 PDF

IETF RFC 8078 PDF

Name:
IETF RFC 8078 PDF

Published Date:
03/01/2017

Status:
[ Withdrawn ]

Description:

Managing DS Records from the Parent via CDS/CDNSKEY

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
Need Help?
W/D S/S BY IETF RFC 9615

RFC 7344 specifies how DNS trust can be maintained across key rollovers in-band between parent and child. This document elevates RFC 7344 from Informational to Standards Track. It also adds a method for initial trust setup and removal of a secure entry point.

Changing a domain’s DNSSEC status can be a complicated matter involving multiple unrelated parties. Some of these parties, such as the DNS operator, might not even be known by all the organizations involved. The inability to disable DNSSEC via in-band signaling is seen as a problem or liability that prevents some DNSSEC adoption at a large scale. This document adds a method for in-band signaling of these DNSSEC status changes.

This document describes reasonable policies to ease deployment of the initial acceptance of new secure entry points (DS records).

It is preferable that operators collaborate on the transfer or move of a domain. The best method is to perform a Key Signing Key (KSK) plus Zone Signing Key (ZSK) rollover. If that is not possible, the method using an unsigned intermediate state described in this document can be used to move the domain between two parties. This leaves the domain temporarily unsigned and vulnerable to DNS spoofing, but that is preferred over the alternative of validation failures due to a mismatched DS and DNSKEY record.


Edition : 17
Number of Pages : 10
Published : 03/01/2017

History


Related products

IETF RFC 3262
Published Date: 06/01/2002
Reliability of Provisional Responses in the Session Initiation Protocol (SIP)
$10.2
IETF RFC 7159
Published Date: 03/01/2014
The JavaScript Object Notation (JSON) Data Interchange Format
$10.2

Best-Selling Products

EA 0004:2001
Published Date: 07/20/2001
Technical specification of supply assembly for high intensity discharge lamps.
EA 0005:2001
Published Date: 07/20/2001
Technical specification of supply assembly for high intensity discharge lamps of double power level.
EA 0006:2002
Published Date: 04/24/2002
Polyvinyl chloride insulated cables to be used in interconnection circuits for household audio equipment.
EA 0007:2002
Published Date: 07/25/2002
Specifications for the checking and aggregation system for recovered paper.
EA 0007:2008
Published Date: 07/30/2008
Specifications for the checking and aggregation system for recovered paper.
EA 0009:2003
Published Date: 01/31/2003
Snub elements of bundle assembled cores for low voltage overhead lines.