Domain Name System KEY Resource Record Secure Entry Point Flag
RFC 3757, “Domain Name System KEY Resource Record Secure Entry Point Flag”, is a Proposed Standard document published in May 2004 by O. Kolkman, J. Schlyter, E. Lewis. It updates RFC 2535, RFC 3755. It has been obsoleted by RFC 4033, RFC 4034, RFC 4035 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
With the Delegation Signer (DS) resource record (RR), the concept of a public key acting as a secure entry point (SEP) has been introduced. During exchanges of public keys with the parent there is a need to differentiate SEP keys from other public keys in the Domain Name System KEY (DNSKEY) resource record set. A flag bit in the DNSKEY RR is defined to indicate that DNSKEY is to be used as a SEP. The flag bit is intended to assist in operational procedures to correctly generate DS resource records, or to indicate what DNSKEYs are intended for static configuration. The flag bit is not to be used in the DNS verification protocol. This document updates RFC 2535 and RFC 3755. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3757 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3756 IPv6 Neighbor Discovery Trust Models and Threats
- RFC 3758 Stream Control Transmission Protocol Partial Reliability Extension
- RFC 3755 Legacy Resolver Compatibility for Delegation Signer
- RFC 3759 RObust Header Compression : Terminology and Channel Mapping Examples
- RFC 3754 IP Multicast in Differentiated Services Networks
- RFC 3760 Securely Available Credentials - Credential Server Framework
- RFC 3753 Mobility Related Terminology
- RFC 3761 The E.164 to Uniform Resource Identifiers Dynamic Delegation Discovery System Application