Measures for Making DNS More Resilient against Forged Answers
RFC 5452, “Measures for Making DNS More Resilient against Forged Answers”, is a Proposed Standard document published in January 2009 by A. Hubert, R. van Mook. It updates RFC 2181. The canonical text is published by the RFC Editor.
Abstract
The current Internet climate poses serious threats to the Domain Name System. In the interim period before the DNS protocol can be secured more fully, measures can already be taken to harden the DNS to make 'spoofing' a recursing nameserver many orders of magnitude harder.
Even a cryptographically secured DNS benefits from having the ability to discard bogus responses quickly, as this potentially saves large amounts of computation.
By describing certain behavior that has previously not been standardized, this document sets out how to make the DNS more resilient against accepting incorrect responses. This document updates RFC 2181. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5452 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5451 Message Header Field for Indicating Message Authentication Status
- RFC 5453 Reserved IPv6 Interface Identifiers
- RFC 5450 Transmission Time Offsets in RTP Streams
- RFC 5454 Dual-Stack Mobile IPv4
- RFC 5449 OSPF Multipoint Relay Extension for Ad Hoc Networks
- RFC 5455 Diffserv-Aware Class-Type Object for the Path Computation Element Communication Protocol
- RFC 5448 Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement
- RFC 5447 Diameter Mobile IPv6: Support for Network Access Server to Diameter Server Interaction