Minimally Covering NSEC Records and DNSSEC On-line Signing
RFC 4470, “Minimally Covering NSEC Records and DNSSEC On-line Signing”, is a Proposed Standard document published in April 2006 by S. Weiler, J. Ihren. It updates RFC 4034, RFC 4035. The canonical text is published by the RFC Editor.
Abstract
This document describes how to construct DNSSEC NSEC resource records that cover a smaller range of names than called for by RFC 4034. By generating and signing these records on demand, authoritative name servers can effectively stop the disclosure of zone contents otherwise made possible by walking the chain of NSEC records in a signed zone. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4470 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4469 Internet Message Access Protocol CATENATE Extension
- RFC 4471 Derivation of DNS Name Predecessor and Successor
- RFC 4468 Message Submission BURL Extension
- RFC 4472 Operational Considerations and Issues with IPv6 DNS
- RFC 4467 Internet Message Access Protocol - URLAUTH Extension
- RFC 4473 Requirements for Internet Media Guides
- RFC 4466 Collected Extensions to IMAP4 ABNF
- RFC 4474 Enhancements for Authenticated Identity Management in the Session Initiation Protocol