RFC 9102 · EXPERIMENTAL · 2021

TLS DNSSEC Chain Extension

Overview

RFC 9102, “TLS DNSSEC Chain Extension”, is an Experimental document published in August 2021 by V. Dukhovni, S. Huque, W. Toorop, P. Wouters, M. Shore. The canonical text is published by the RFC Editor.

Abstract

This document describes an experimental TLS extension for the in-band transport of the complete set of records that can be validated by DNSSEC and that are needed to perform DNS-Based Authentication of Named Entities (DANE) of a TLS server. This extension obviates the need to perform separate, out-of-band DNS lookups. When the requisite DNS records do not exist, the extension conveys a denial-of-existence proof that can be validated.

This experimental extension is developed outside the IETF and is published here to guide implementation of the extension and to ensure interoperability among implementations.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 9102 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2021

Who Is Online

In total there are 143 users online: 0 registered, 136 guests and 7 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Bingbot Majestic Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 354