Signaling Trust Anchor Knowledge in DNS Security Extensions
RFC 8145, “Signaling Trust Anchor Knowledge in DNS Security Extensions”, is a Proposed Standard document published in April 2017 by D. Wessels, W. Kumari, P. Hoffman. It has since been updated by RFC 8553. The canonical text is published by the RFC Editor.
Abstract
The DNS Security Extensions (DNSSEC) were developed to provide origin authentication and integrity protection for DNS data by using digital signatures. These digital signatures can be verified by building a chain of trust starting from a trust anchor and proceeding down to a particular node in the DNS. This document specifies two different ways for validating resolvers to signal to a server which keys are referenced in their chain of trust. The data from such signaling allow zone administrators to monitor the progress of rollovers in a DNSSEC-signed zone.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8145 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8144 Use of the Prefer Header Field in Web Distributed Authoring and Versioning
- RFC 8146 Adding Support for Salted Password Databases to EAP-pwd
- RFC 8143 Using Transport Layer Security with Network News Transfer Protocol
- RFC 8147 Next-Generation Pan-European eCall
- RFC 8142 GeoJSON Text Sequences
- RFC 8148 Next-Generation Vehicle-Initiated Emergency Calls
- RFC 8141 Uniform Resource Names
- RFC 8149 RSVP Extensions for Reoptimization of Loosely Routed Point-to- Multipoint Traffic Engineering Label Switched Paths