RFC 8901 · INFORMATIONAL · 2020

Multi-Signer DNSSEC Models

Overview

RFC 8901, “Multi-Signer DNSSEC Models”, is an Informational document published in September 2020 by S. Huque, P. Aras, J. Dickinson, J. Vcelak, D. Blacka. The canonical text is published by the RFC Editor.

Abstract

Many enterprises today employ the service of multiple DNS providers to distribute their authoritative DNS service. Deploying DNSSEC in such an environment may present some challenges, depending on the configuration and feature set in use. In particular, when each DNS provider independently signs zone data with their own keys, additional key-management mechanisms are necessary. This document presents deployment models that accommodate this scenario and describes these key-management requirements. These models do not require any changes to the behavior of validating resolvers, nor do they impose the new key-management requirements on authoritative servers not involved in multi-signer configurations.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 8901 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2020

Who Is Online

In total there are 77 users online: 0 registered, 74 guests and 3 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354