Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's Operator
RFC 9615, “Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's Operator”, is a Proposed Standard document published in July 2024 by P. Thomassen, N. Wisiol. It updates RFC 7344, RFC 8078. The canonical text is published by the RFC Editor.
Abstract
This document introduces an in-band method for DNS operators to publish arbitrary information about the zones for which they are authoritative, in an authenticated fashion and on a per-zone basis. The mechanism allows managed DNS operators to securely announce DNSSEC key parameters for zones under their management, including for zones that are not currently securely delegated.
Whenever DS records are absent for a zone's delegation, this signal enables the parent's registry or registrar to cryptographically validate the CDS/CDNSKEY records found at the child's apex. The parent can then provision DS records for the delegation without resorting to out-of-band validation or weaker types of cross-checks such as "Accept after Delay".
This document establishes the DS enrollment method described in Section 4 of this document as the preferred method over those from Section 3 of RFC 8078. It also updates RFC 7344.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9615 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9614 Partitioning as an Architecture for Privacy
- RFC 9616 Delay-Based Metric Extension for the Babel Routing Protocol
- RFC 9613 Requirements for Solutions that Support MPLS Network Actions
- RFC 9617 A YANG Data Model for In Situ Operations, Administration, and Maintenance
- RFC 9612 Bidirectional Forwarding Detection Reverse Path for MPLS Label Switched Paths
- RFC 9618 Updates to X.509 Policy Validation
- RFC 9611 Internet Key Exchange Protocol Version 2 Support for Per- Resource Child Security Associations
- RFC 9619 In the DNS, QDCOUNT Is One