Requirements Related to DNS Security Trust Anchor Rollover
RFC 4986, “Requirements Related to DNS Security Trust Anchor Rollover”, is an Informational document published in August 2007 by H. Eland, R. Mundy, S. Crocker, S. Krishnaswamy. The canonical text is published by the RFC Editor.
Abstract
Every DNS security-aware resolver must have at least one Trust Anchor to use as the basis for validating responses from DNS signed zones. For various reasons, most DNS security-aware resolvers are expected to have several Trust Anchors. For some operations, manual monitoring and updating of Trust Anchors may be feasible, but many operations will require automated methods for updating Trust Anchors in their security-aware resolvers. This document identifies the requirements that must be met by an automated DNS Trust Anchor rollover solution for security-aware DNS resolvers. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4986 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4985 Internet X.509 Public Key Infrastructure Subject Alternative Name for Expression of Service Name
- RFC 4987 TCP SYN Flooding Attacks and Common Mitigations
- RFC 4984 Report from the IAB Workshop on Routing and Addressing
- RFC 4988 Mobile IPv4 Fast Handovers
- RFC 4983 Fibre Channel Registered State Change Notification MIB
- RFC 4982 Support for Multiple Hash Algorithms in Cryptographically Generated Addresses
- RFC 4990 Use of Addresses in Generalized Multiprotocol Label Switching Networks
- RFC 4981 Survey of Research towards Robust Peer-to-Peer Networks: Search Methods