Limiting the Scope of the KEY Resource Record
RFC 3445, “Limiting the Scope of the KEY Resource Record”, is a Proposed Standard document published in December 2002 by D. Massey, S. Rose. It updates RFC 2535. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document limits the Domain Name System (DNS) KEY Resource Record (RR) to only keys used by the Domain Name System Security Extensions (DNSSEC). The original KEY RR used sub-typing to store both DNSSEC keys and arbitrary application keys. Storing both DNSSEC and application keys with the same record type is a mistake. This document removes application keys from the KEY record by redefining the Protocol Octet field in the KEY RR Data. As a result of removing application keys, all but one of the flags in the KEY record become unnecessary and are redefined. Three existing application key sub-types are changed to reserved, but the format of the KEY record is not changed. This document updates RFC 2535. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3445 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3442 The Classless Static Route Option for Dynamic Host Configuration Protocol version 4
- RFC 3449 TCP Performance Implications of Network Path Asymmetry
- RFC 3450 Asynchronous Layered Coding Protocol Instantiation
- RFC 3439 Some Internet Architectural Guidelines and Philosophy
- RFC 3451 Layered Coding Transport Building Block
- RFC 3438 Layer Two Tunneling Protocol Internet Assigned Numbers Authority Considerations Update
- RFC 3452 Forward Error Correction Building Block
- RFC 3453 The Use of Forward Error Correction in Reliable Multicast