RFC 4986 · INFORMATIONAL · 2007

Requirements Related to DNS Security Trust Anchor Rollover

Overview

RFC 4986, “Requirements Related to DNS Security Trust Anchor Rollover”, is an Informational document published in August 2007 by H. Eland, R. Mundy, S. Crocker, S. Krishnaswamy. The canonical text is published by the RFC Editor.

Abstract

Every DNS security-aware resolver must have at least one Trust Anchor to use as the basis for validating responses from DNS signed zones. For various reasons, most DNS security-aware resolvers are expected to have several Trust Anchors. For some operations, manual monitoring and updating of Trust Anchors may be feasible, but many operations will require automated methods for updating Trust Anchors in their security-aware resolvers. This document identifies the requirements that must be met by an automated DNS Trust Anchor rollover solution for security-aware DNS resolvers. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 4986 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2007

Who Is Online

In total there are 339 users online: 0 registered, 329 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler Other Spider PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372