Unilateral Opportunistic Deployment of Encrypted Recursive-to- Authoritative DNS
RFC 9539, “Unilateral Opportunistic Deployment of Encrypted Recursive-to- Authoritative DNS”, is an Experimental document published in February 2024 by D. K. Gillmor, J. Salazar, P. Hoffman. The canonical text is published by the RFC Editor.
Abstract
This document sets out steps that DNS servers (recursive resolvers and authoritative servers) can take unilaterally (without any coordination with other peers) to defend DNS query privacy against a passive network monitor. The protections provided by the guidance in this document can be defeated by an active attacker, but they should be simpler and less risky to deploy than more powerful defenses.
The goal of this document is to simplify and speed up deployment of opportunistic encrypted transport in the recursive-to-authoritative hop of the DNS ecosystem. Wider easy deployment of the underlying encrypted transport on an opportunistic basis may facilitate the future specification of stronger cryptographic protections against more-powerful attacks.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 9539 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9538 Content Delivery Network Interconnection Delegation Using the Automated Certificate Management Environment
- RFC 9540 Discovery of Oblivious Services via Service Binding Records
- RFC 9537 Redacted Fields in the Registration Data Access Protocol Response
- RFC 9541 Flush Mechanism for Customer MAC Addresses Based on Service Instance Identifier in Provider Backbone Bridging EVPN
- RFC 9536 Registration Data Access Protocol Reverse Search
- RFC 9542 IANA Considerations and IETF Protocol and Documentation Usage for IEEE 802 Parameters
- RFC 9535 JSONPath: Query Expressions for JSON
- RFC 9543 A Framework for Network Slices in Networks Built from IETF Technologies