Domain Name System Security Signing Authority
RFC 3008, “Domain Name System Security Signing Authority”, is a Proposed Standard document published in November 2000 by B. Wellington. It updates RFC 2535. It has since been updated by RFC 3658. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document proposes a revised model of Domain Name System Security (DNSSEC) Signing Authority. The revised model is designed to clarify earlier documents and add additional restrictions to simplify the secure resolution process. Specifically, this affects the authorization of keys to sign sets of records. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3008 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3007 Secure Domain Name System Dynamic Update
- RFC 3009 Registration of parityfec MIME types
- RFC 3006 Integrated Services in the Presence of Compressible Flows
- RFC 3010 NFS version 4 Protocol
- RFC 3005 IETF Discussion List Charter
- RFC 3011 The IPv4 Subnet Selection Option for DHCP
- RFC 3004 The User Class Option for DHCP
- RFC 3012 Mobile IPv4 Challenge/Response Extensions