Delegation Signer Resource Record
RFC 3658, “Delegation Signer Resource Record”, is a Proposed Standard document published in December 2003 by O. Gudmundsson. It updates RFC 1035, RFC 2535, RFC 3008, RFC 3090. It has since been updated by RFC 3755. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
The delegation signer (DS) resource record (RR) is inserted at a zone cut (i.e., a delegation point) to indicate that the delegated zone is digitally signed and that the delegated zone recognizes the indicated key as a valid zone key for the delegated zone. The DS RR is a modification to the DNS Security Extensions definition, motivated by operational considerations. The intent is to use this resource record as an explicit statement about the delegation, rather than relying on inference. This document defines the DS RR, gives examples of how it is used and describes the implications on resolvers. This change is not backwards compatible with RFC 2535. This document updates RFC 1035, RFC 2535, RFC 3008 and RFC 3090.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3658 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3656 The Mailbox Update Distributed Mailbox Database Protocol
- RFC 3660 Basic Media Gateway Control Protocol Packages
- RFC 3655 Redefinition of DNS Authenticated Data bit
- RFC 3661 Media Gateway Control Protocol Return Code Usage
- RFC 3654 Requirements for Separation of IP Control and Forwarding
- RFC 3662 A Lower Effort Per-Domain Behavior for Differentiated Services
- RFC 3653 XML-Signature XPath Filter 2.0
- RFC 3663 Domain Administrative Data in Lightweight Directory Access Protocol