Legacy Resolver Compatibility for Delegation Signer
RFC 3755, “Legacy Resolver Compatibility for Delegation Signer”, is a Proposed Standard document published in May 2004 by S. Weiler. It updates RFC 2535, RFC 3658. It has since been updated by RFC 3757, RFC 3845. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
As the DNS Security (DNSSEC) specifications have evolved, the syntax and semantics of the DNSSEC resource records (RRs) have changed. Many deployed nameservers understand variants of these semantics. Dangerous interactions can occur when a resolver that understands an earlier version of these semantics queries an authoritative server that understands the new delegation signer semantics, including at least one failure scenario that will cause an unsecured zone to be unresolvable. This document changes the type codes and mnemonics of the DNSSEC RRs (SIG, KEY, and NXT) to avoid those interactions. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3755 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3754 IP Multicast in Differentiated Services Networks
- RFC 3756 IPv6 Neighbor Discovery Trust Models and Threats
- RFC 3753 Mobility Related Terminology
- RFC 3757 Domain Name System KEY Resource Record Secure Entry Point Flag
- RFC 3752 Open Pluggable Edge Services Use Cases and Deployment Scenarios
- RFC 3758 Stream Control Transmission Protocol Partial Reliability Extension
- RFC 3751 Omniscience Protocol Requirements
- RFC 3759 RObust Header Compression : Terminology and Channel Mapping Examples