RFC 3757 · PROPOSED STANDARD · 2004

Domain Name System KEY Resource Record Secure Entry Point Flag

Overview

RFC 3757, “Domain Name System KEY Resource Record Secure Entry Point Flag”, is a Proposed Standard document published in May 2004 by O. Kolkman, J. Schlyter, E. Lewis. It updates RFC 2535, RFC 3755. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

With the Delegation Signer (DS) resource record (RR), the concept of a public key acting as a secure entry point (SEP) has been introduced. During exchanges of public keys with the parent there is a need to differentiate SEP keys from other public keys in the Domain Name System KEY (DNSKEY) resource record set. A flag bit in the DNSKEY RR is defined to indicate that DNSKEY is to be used as a SEP. The flag bit is intended to assist in operational procedures to correctly generate DS resource records, or to indicate what DNSKEYs are intended for static configuration. The flag bit is not to be used in the DNS verification protocol. This document updates RFC 2535 and RFC 3755. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 3757 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 4033 RFC 4034 RFC 4035
This RFC updates
RFC 2535 RFC 3755
Other RFCs from 2004

Who Is Online

In total there are 43 users online: 0 registered, 36 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372