Guidance for NSEC3 Parameter Settings
RFC 9276, “Guidance for NSEC3 Parameter Settings”, is a Best Current Practice document published in August 2022 by W. Hardaker, V. Dukhovni. It updates RFC 5155. The canonical text is published by the RFC Editor.
Abstract
NSEC3 is a DNSSEC mechanism providing proof of nonexistence by asserting that there are no names that exist between two domain names within a zone. Unlike its counterpart NSEC, NSEC3 avoids directly disclosing the bounding domain name pairs. This document provides guidance on setting NSEC3 parameters based on recent operational deployment experience. This document updates RFC 5155 with guidance about selecting NSEC3 iteration and salt parameters.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 9276 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9275 An Extension for Application-Layer Traffic Optimization : Path Vector
- RFC 9277 On Stable Storage for Items in Concise Binary Object Representation
- RFC 9274 A Cost Mode Registry for the Application-Layer Traffic Optimization Protocol
- RFC 9278 JWK Thumbprint URI
- RFC 9273 Network Coding for Content-Centric Networking / Named Data Networking: Considerations and Challenges
- RFC 9279 Internet Group Management Protocol Version 3 and Multicast Listener Discovery Version 2 Message Extension
- RFC 9272 Underlay Path Calculation Algorithm and Constraints for Bit Index Explicit Replication
- RFC 9280 RFC Editor Model