Storing Certificates in the Domain Name System
RFC 2538, “Storing Certificates in the Domain Name System”, is a Proposed Standard document published in March 1999 by D. Eastlake 3rd, O. Gudmundsson. It has been obsoleted by RFC 4398 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
Cryptographic public key are frequently published and their authenticity demonstrated by certificates. A CERT resource record (RR) is defined so that such certificates and related certificate revocation lists can be stored in the Domain Name System (DNS). [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 2538 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 2537 RSA/MD5 KEYs and SIGs in the Domain Name System
- RFC 2539 Storage of Diffie-Hellman Keys in the Domain Name System
- RFC 2536 DSA KEYs and SIGs in the Domain Name System
- RFC 2540 Detached Domain Name System Information
- RFC 2535 Domain Name System Security Extensions
- RFC 2541 DNS Security Operational Considerations
- RFC 2534 Media Features for Display, Print, and Fax
- RFC 2542 Terminology and Goals for Internet Fax