Secret Key Transaction Authentication for DNS
RFC 8945, “Secret Key Transaction Authentication for DNS”, is an Internet Standard document published in November 2020 by F. Dupont, S. Morris, P. Vixie, D. Eastlake 3rd, O. Gudmundsson, B. Wellington. It obsoletes RFC 2845, RFC 4635. The canonical text is published by the RFC Editor.
Abstract
This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server.
No recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism.
This document obsoletes RFCs 2845 and 4635.
What “Internet Standard” means
A mature, widely-implemented specification that has completed the full IETF standards process — the highest maturity level on the standards track.
The canonical text of RFC 8945 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8944 A YANG Data Model for Layer 2 Network Topologies
- RFC 8943 Concise Binary Object Representation Tags for Date
- RFC 8947 Link-Layer Address Assignment Mechanism for DHCPv6
- RFC 8948 Structured Local Address Plan Quadrant Selection Option for DHCPv6
- RFC 8949 Concise Binary Object Representation
- RFC 8940 Extensible Authentication Protocol Session-Id Derivation for EAP Subscriber Identity Module , EAP Authentication and Key Agreement , and Protected EAP
- RFC 8950 Advertising IPv4 Network Layer Reachability Information with an IPv6 Next Hop
- RFC 8939 Deterministic Networking Data Plane: IP