RFC 6781 · INFORMATIONAL · 2012

DNSSEC Operational Practices, Version 2

Overview

RFC 6781, “DNSSEC Operational Practices, Version 2”, is an Informational document published in December 2012 by O. Kolkman, W. Mekking, R. Gieben. It obsoletes RFC 4641. The canonical text is published by the RFC Editor.

Abstract

This document describes a set of practices for operating the DNS with security extensions (DNSSEC). The target audience is zone administrators deploying DNSSEC.

The document discusses operational aspects of using keys and signatures in the DNS. It discusses issues of key generation, key storage, signature generation, key rollover, and related policies.

This document obsoletes RFC 4641, as it covers more operational ground and gives more up-to-date requirements with respect to key sizes and the DNSSEC operations.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 6781 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC obsoletes
RFC 4641
Other RFCs from 2012

Who Is Online

In total there are 53 users online: 0 registered, 46 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372