Indicating Resolver Support of DNSSEC
RFC 3225, “Indicating Resolver Support of DNSSEC”, is a Proposed Standard document published in December 2001 by D. Conrad. It has since been updated by RFC 4033, RFC 4034, RFC 4035. The canonical text is published by the RFC Editor.
Abstract
In order to deploy DNSSEC (Domain Name System Security Extensions) operationally, DNSSEC aware servers should only perform automatic inclusion of DNSSEC RRs when there is an explicit indication that the resolver can understand those RRs. This document proposes the use of a bit in the EDNS0 header to provide that explicit indication and describes the necessary protocol changes to implement that notification. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3225 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3226 DNSSEC and IPv6 A6 aware server/resolver message size requirements
- RFC 3222 Terminology for Forwarding Information Base based Router Performance
- RFC 3221 Commentary on Inter-Domain Routing in the Internet
- RFC 3217 Triple-DES and RC2 Key Wrapping
- RFC 3216 SMIng Objectives
- RFC 3211 Password-based Encryption for CMS
- RFC 3210 Applicability Statement for Extensions to RSVP for LSP-Tunnels
- RFC 3209 RSVP-TE: Extensions to RSVP for LSP Tunnels