Protocol Modifications for the DNS Security Extensions
This specification has been revised 12 times since RFC 2065 (1997). Each document below formally obsoleted the one before it; the versions still in force are listed first.
Revision timeline
Current versions — implement against these
Superseded versions — historical reference only
- RFC 2065Domain Name System Security ExtensionsObsoletedJanuary 1997proposed standardreplaced by RFC2535
- RFC 2535Domain Name System Security ExtensionsObsoletedMarch 1999proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3008Domain Name System Security (DNSSEC) Signing AuthorityObsoletedNovember 2000proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3090DNS Security Extension Clarification on Zone StatusObsoletedMarch 2001proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3445Limiting the Scope of the KEY Resource Record (RR)ObsoletedDecember 2002proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3655Redefinition of DNS Authenticated Data (AD) bitObsoletedNovember 2003proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3658Delegation Signer (DS) Resource Record (RR)ObsoletedDecember 2003proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)ObsoletedMay 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3757Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) FlagObsoletedMay 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoletedAugust 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
This lineage is derived automatically from the “obsoletes” relationships recorded in the public RFC Editor index — no editorial judgement is applied to the ordering. The most recent document in the chain is RFC 4035 (March 2005).