RFC 3008 · PROPOSED STANDARD · 2000

Domain Name System Security Signing Authority

Overview

RFC 3008, “Domain Name System Security Signing Authority”, is a Proposed Standard document published in November 2000 by B. Wellington. It updates RFC 2535. It has since been updated by RFC 3658. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

This document proposes a revised model of Domain Name System Security (DNSSEC) Signing Authority. The revised model is designed to clarify earlier documents and add additional restrictions to simplify the secure resolution process. Specifically, this affects the authorization of keys to sign sets of records. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 3008 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 4033 RFC 4034 RFC 4035
This RFC updates
RFC 2535
Updated by
RFC 3658
Other RFCs from 2000

Who Is Online

In total there are 43 users online: 0 registered, 36 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372