Message Digest for DNS Zones
RFC 8976, “Message Digest for DNS Zones”, is a Proposed Standard document published in February 2021 by D. Wessels, P. Barber, M. Weinberg, W. Kumari, W. Hardaker. The canonical text is published by the RFC Editor.
Abstract
This document describes a protocol and new DNS Resource Record that provides a cryptographic message digest over DNS zone data at rest. The ZONEMD Resource Record conveys the digest data in the zone itself. When used in combination with DNSSEC, ZONEMD allows recipients to verify the zone contents for data integrity and origin authenticity. This provides assurance that received zone data matches published data, regardless of how the zone data has been transmitted and received. When used without DNSSEC, ZONEMD functions as a checksum, guarding only against unintentional changes.
ZONEMD does not replace DNSSEC: DNSSEC protects individual RRsets (DNS data with fine granularity), whereas ZONEMD protects a zone's data as a whole, whether consumed by authoritative name servers, recursive name servers, or any other applications.
As specified herein, ZONEMD is impractical for large, dynamic zones due to the time and resources required for digest calculation. However, the ZONEMD record is extensible so that new digest schemes may be added in the future to support large, dynamic zones.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8976 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8975 Network Coding for Satellite Systems
- RFC 8977 Registration Data Access Protocol Query Parameters for Result Sorting and Paging
- RFC 8974 Extended Tokens and Stateless Clients in the Constrained Application Protocol
- RFC 8978 Reaction of IPv6 Stateless Address Autoconfiguration to Flash-Renumbering Events
- RFC 8973 DDoS Open Threat Signaling Agent Discovery
- RFC 8979 Subscriber and Performance Policy Identifier Context Headers in the Network Service Header
- RFC 8972 Simple Two-Way Active Measurement Protocol Optional Extensions
- RFC 8980 Report from the IAB Workshop on Design Expectations vs