DNSSEC Operational Practices, Version 2
RFC 6781, “DNSSEC Operational Practices, Version 2”, is an Informational document published in December 2012 by O. Kolkman, W. Mekking, R. Gieben. It obsoletes RFC 4641. The canonical text is published by the RFC Editor.
Abstract
This document describes a set of practices for operating the DNS with security extensions (DNSSEC). The target audience is zone administrators deploying DNSSEC.
The document discusses operational aspects of using keys and signatures in the DNS. It discusses issues of key generation, key storage, signature generation, key rollover, and related policies.
This document obsoletes RFC 4641, as it covers more operational ground and gives more up-to-date requirements with respect to key sizes and the DNSSEC operations.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6781 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6780 RSVP ASSOCIATION Object Extensions
- RFC 6782 Wireline Incremental IPv6
- RFC 6779 Definition of Managed Objects for the Neighborhood Discovery Protocol
- RFC 6783 Mailing Lists and Non-ASCII Addresses
- RFC 6778 Requirements for Archiving IETF Email Lists and for Providing Web- Based Browsing and Searching
- RFC 6784 Kerberos Options for DHCPv6
- RFC 6777 Label Switched Path Data Path Delay Metrics in Generalized MPLS and MPLS Traffic Engineering Networks
- RFC 6785 Support for Internet Message Access Protocol Events in Sieve