DNS-Based Authentication of Named Entities Bindings for OpenPGP
RFC 7929, “DNS-Based Authentication of Named Entities Bindings for OpenPGP”, is an Experimental document published in August 2016 by P. Wouters. The canonical text is published by the RFC Editor.
Abstract
OpenPGP is a message format for email (and file) encryption that lacks a standardized lookup mechanism to securely obtain OpenPGP public keys. DNS-Based Authentication of Named Entities (DANE) is a method for publishing public keys in DNS. This document specifies a DANE method for publishing and locating OpenPGP public keys in DNS for a specific email address using a new OPENPGPKEY DNS resource record. Security is provided via Secure DNS, however the OPENPGPKEY record is not a replacement for verification of authenticity via the "web of trust" or manual verification. The OPENPGPKEY record can be used to encrypt an email that would otherwise have to be sent unencrypted.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 7929 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7928 Characterization Guidelines for Active Queue Management
- RFC 7930 Larger Packets for RADIUS over TCP
- RFC 7927 Information-Centric Networking Research Challenges
- RFC 7931 NFSv4.0 Migration: Specification Update
- RFC 7926 Problem Statement and Architecture for Information Exchange between Interconnected Traffic-Engineered Networks
- RFC 7932 Brotli Compressed Data Format
- RFC 7925 Transport Layer Security / Datagram Transport Layer Security Profiles for the Internet of Things
- RFC 7933 Adaptive Video Streaming over Information-Centric Networking