Clarifications and Implementation Notes for DNS Security
RFC 6840, “Clarifications and Implementation Notes for DNS Security”, is a Proposed Standard document published in February 2013 by S. Weiler, D. Blacka. It updates RFC 4033, RFC 4034, RFC 4035, RFC 5155. It has since been updated by RFC 8749. The canonical text is published by the RFC Editor.
Abstract
This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.
This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6840 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6839 Additional Media Type Structured Syntax Suffixes
- RFC 6841 A Framework for DNSSEC Policies and DNSSEC Practice Statements
- RFC 6838 Media Type Specifications and Registration Procedures
- RFC 6842 Client Identifier Option in DHCP Server Replies
- RFC 6837 NERD: A Not-so-novel Endpoint ID to Routing Locator Database
- RFC 6843 RTP Control Protocol Extended Report Block for Delay Metric Reporting
- RFC 6836 Locator/ID Separation Protocol Alternative Logical Topology
- RFC 6844 DNS Certification Authority Authorization Resource Record