Aggressive Use of DNSSEC-Validated Cache
RFC 8198, “Aggressive Use of DNSSEC-Validated Cache”, is a Proposed Standard document published in July 2017 by K. Fujiwara, A. Kato, W. Kumari. It updates RFC 4035. It has since been updated by RFC 9077. The canonical text is published by the RFC Editor.
Abstract
The DNS relies upon caching to scale; however, the cache lookup generally requires an exact match. This document specifies the use of NSEC/NSEC3 resource records to allow DNSSEC-validating resolvers to generate negative answers within a range and positive answers from wildcards. This increases performance, decreases latency, decreases resource utilization on both authoritative and recursive servers, and increases privacy. Also, it may help increase resilience to certain DoS attacks in some circumstances.
This document updates RFC 4035 by allowing validating resolvers to generate negative answers based upon NSEC/NSEC3 records and positive answers in the presence of wildcards.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8198 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8197 A SIP Response Code for Unwanted Calls
- RFC 8199 YANG Module Classification
- RFC 8196 IS-IS Autoconfiguration
- RFC 8200 Internet Protocol, Version 6 Specification
- RFC 8195 Use of BGP Large Communities
- RFC 8201 Path MTU Discovery for IP version 6
- RFC 8194 A YANG Data Model for LMAP Measurement Agents
- RFC 8202 IS-IS Multi-Instance