DNS Security Hashed Authenticated Denial of Existence
RFC 5155, “DNS Security Hashed Authenticated Denial of Existence”, is a Proposed Standard document published in March 2008 by B. Laurie, G. Sisson, R. Arends, D. Blacka. It has since been updated by RFC 6840, RFC 6944, RFC 9077, RFC 9157, RFC 9276, RFC 9905. The canonical text is published by the RFC Editor.
Abstract
The Domain Name System Security (DNSSEC) Extensions introduced the NSEC resource record (RR) for authenticated denial of existence. This document introduces an alternative resource record, NSEC3, which similarly provides authenticated denial of existence. However, it also provides measures against zone enumeration and permits gradual expansion of delegation-centric zones. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5155 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5154 IP over IEEE 802.16 Problem Statement and Goals
- RFC 5156 Special-Use IPv6 Addresses
- RFC 5153 IP Flow Information Export Implementation Guidelines
- RFC 5157 IPv6 Implications for Network Scanning
- RFC 5152 A Per-Domain Path Computation Method for Establishing Inter-Domain Traffic Engineering Label Switched Paths
- RFC 5158 6to4 Reverse DNS Delegation Specification
- RFC 5151 Inter-Domain MPLS and GMPLS Traffic Engineering -- Resource Reservation Protocol-Traffic Engineering Extensions
- RFC 5159 Session Description Protocol Attributes for Open Mobile Alliance Broadcast Service and Content Protection