RFC 4641 · INFORMATIONAL · 2006

DNSSEC Operational Practices

Overview

RFC 4641, “DNSSEC Operational Practices”, is an Informational document published in September 2006 by O. Kolkman, R. Gieben. It obsoletes RFC 2541. It has been obsoleted by RFC 6781 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

This document describes a set of practices for operating the DNS with security extensions (DNSSEC). The target audience is zone administrators deploying DNSSEC.

The document discusses operational aspects of using keys and signatures in the DNS. It discusses issues of key generation, key storage, signature generation, key rollover, and related policies.

This document obsoletes RFC 2541, as it covers more operational ground and gives more up-to-date requirements with respect to key sizes and the new DNSSEC specification. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 4641 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC obsoletes
RFC 2541
Obsoleted by
RFC 6781
Other RFCs from 2006

Who Is Online

In total there are 448 users online: 0 registered, 443 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Facebook Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 354