Storing Certificates in the Domain Name System
RFC 4398, “Storing Certificates in the Domain Name System”, is a Proposed Standard document published in March 2006 by S. Josefsson. It obsoletes RFC 2538. It has since been updated by RFC 6944. The canonical text is published by the RFC Editor.
Abstract
Cryptographic public keys are frequently published, and their authenticity is demonstrated by certificates. A CERT resource record (RR) is defined so that such certificates and related certificate revocation lists can be stored in the Domain Name System (DNS). [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4398 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4397 A Lexicography for the Interpretation of Generalized Multiprotocol Label Switching Terminology within the Context of the ITU-T's Automatically Switched Optical Network Architecture
- RFC 4396 RTP Payload Format for 3rd Generation Partnership Project Timed Text
- RFC 4395 Guidelines and Registration Procedures for New URI Schemes
- RFC 4401 A Pseudo-Random Function API Extension for the Generic Security Service Application Program Interface
- RFC 4394 A Transport Network View of the Link Management Protocol
- RFC 4402 A Pseudo-Random Function for the Kerberos V Generic Security Service Application Program Interface Mechanism
- RFC 4393 MIME Type Registrations for 3GPP2 Multimedia Files
- RFC 4403 Lightweight Directory Access Protocol Schema for Universal Description, Discovery, and Integration version 3