The DNS-Based Authentication of Named Entities Transport Layer Security Protocol: TLSA
RFC 6698, “The DNS-Based Authentication of Named Entities Transport Layer Security Protocol: TLSA”, is a Proposed Standard document published in August 2012 by P. Hoffman, J. Schlyter. It has since been updated by RFC 7218, RFC 7671, RFC 8749. The canonical text is published by the RFC Editor.
Abstract
Encrypted communication on the Internet often uses Transport Layer Security (TLS), which depends on third parties to certify the keys used. This document improves on that situation by enabling the administrators of domain names to specify the keys used in that domain's TLS servers. This requires matching improvements in TLS client software, but no change in TLS server software. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6698 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6697 Handover Keying Architecture Design
- RFC 6696 EAP Extensions for the EAP Re-authentication Protocol
- RFC 6695 Methods to Convey Forward Error Correction Framework Configuration Information
- RFC 6701 Sanctions Available for Application to Violators of IETF IPR Policy
- RFC 6694 The "about" URI Scheme
- RFC 6702 Promoting Compliance with Intellectual Property Rights Disclosure Rules
- RFC 6693 Probabilistic Routing Protocol for Intermittently Connected Networks
- RFC 6703 Reporting IP Network Performance Metrics: Different Points of View