Secret Key Transaction Authentication for DNS
RFC 2845, “Secret Key Transaction Authentication for DNS”, is a Proposed Standard document published in May 2000 by P. Vixie, O. Gudmundsson, D. Eastlake 3rd, B. Wellington. It updates RFC 1035. It has since been updated by RFC 3645, RFC 4635, RFC 6895. It has been obsoleted by RFC 8945 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This protocol allows for transaction level authentication using shared secrets and one way hashing. It can be used to authenticate dynamic updates as coming from an approved client, or to authenticate responses as coming from an approved recursive name server. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 2845 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 2844 OSPF over ATM and Proxy-PAR
- RFC 2846 GSTN Address Element Extensions in E-mail Services
- RFC 2843 Proxy-PAR
- RFC 2847 LIPKEY - A Low Infrastructure Public Key Mechanism Using SPKM
- RFC 2842 Capabilities Advertisement with BGP-4
- RFC 2848 The PINT Service Protocol: Extensions to SIP and SDP for IP Access to Telephone Call Services
- RFC 2841 IP Authentication using Keyed SHA1 with Interleaved Padding
- RFC 2849 The LDAP Data Interchange Format - Technical Specification