Redefinition of DNS Authenticated Data bit
RFC 3655, “Redefinition of DNS Authenticated Data bit”, is a Proposed Standard document published in November 2003 by B. Wellington, O. Gudmundsson. It updates RFC 2535. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document alters the specification defined in RFC 2535. Based on implementation experience, the Authenticated Data (AD) bit in the DNS header is not useful. This document redefines the AD bit such that it is only set if all answers or records proving that no answers exist in the response has been cryptographically verified or otherwise meets the server's local security policy.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3655 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3654 Requirements for Separation of IP Control and Forwarding
- RFC 3656 The Mailbox Update Distributed Mailbox Database Protocol
- RFC 3653 XML-Signature XPath Filter 2.0
- RFC 3652 Handle System Protocol Specification
- RFC 3658 Delegation Signer Resource Record
- RFC 3651 Handle System Namespace and Service Definition
- RFC 3650 Handle System Overview
- RFC 3660 Basic Media Gateway Control Protocol Packages