NSEC and NSEC3: TTLs and Aggressive Use
RFC 9077, “NSEC and NSEC3: TTLs and Aggressive Use”, is a Proposed Standard document published in July 2021 by P. van Dijk. It updates RFC 4034, RFC 4035, RFC 5155, RFC 8198. The canonical text is published by the RFC Editor.
Abstract
Due to a combination of unfortunate wording in earlier documents, aggressive use of NSEC and NSEC3 records may deny the existence of names far beyond the intended lifetime of a denial. This document changes the definition of the NSEC and NSEC3 TTL to correct that situation. This document updates RFCs 4034, 4035, 5155, and 8198.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9077 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9076 DNS Privacy Considerations
- RFC 9078 Reaction: Indicating Summary Reaction to a Message
- RFC 9075 Report from the IAB COVID-19 Network Impacts Workshop 2020
- RFC 9079 Source-Specific Routing in the Babel Routing Protocol
- RFC 9074 "VALARM" Extensions for iCalendar
- RFC 9080 Homenet Profile of the Babel Routing Protocol
- RFC 9073 Event Publishing Extensions to iCalendar
- RFC 9081 Interoperation between Multicast Virtual Private Network and Multicast Source Directory Protocol Source-Active Routes