RFC 2535: Domain Name System Security Extensions
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 4033, RFC 4034, RFC 4035.
Current document in this lineage: RFC 4033 — DNS Security Introduction and Requirements; RFC 4034 — Resource Records for the DNS Security Extensions; RFC 4035 — Protocol Modifications for the DNS Security Extensions
In plain English — editorial summary, not part of the RFC
This document incorporates feedback on RFC 2065 from early implementers and potential users. [STANDARDS-TRACK]
Document record
- Document ID
- RFC2535
- Published
- March 1999
- Authors
- D. Eastlake 3rd
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 47
- Also known as
- —
- Obsoletes:
- RFC 2065
Topics
Standards lineage
This document is one revision in a chain of 13 RFCs, each formally replacing the one before it.
- RFC 2065 (1997)
- RFC 2535 (1999)
- RFC 3008 (2000)
- RFC 3090 (2001)
- RFC 3445 (2002)
- RFC 3655 (2003)
- RFC 3658 (2003)
- RFC 3755 (2004)
- RFC 3757 (2004)
- RFC 3845 (2004)
- RFC 4033 (2005)
- RFC 4034 (2005)
- RFC 4035 (2005) ✓
Read the full history of Protocol Modifications for the DNS Security Extensions →
Referenced by
15 later RFCs formally update or obsolete part of this document.
- RFC 2931DNS Request and Transaction Signatures ( SIG(0)s )Current
September 2000
- RFC 3007Secure Domain Name System (DNS) Dynamic UpdateCurrent
November 2000
- RFC 3008Domain Name System Security (DNSSEC) Signing AuthorityObsoleted
November 2000
- RFC 3090DNS Security Extension Clarification on Zone StatusObsoleted
March 2001
- RFC 3226DNSSEC and IPv6 A6 aware server/resolver message size requirementsUpdated
December 2001
- RFC 3445Limiting the Scope of the KEY Resource Record (RR)Obsoleted
December 2002
- RFC 3597Handling of Unknown DNS Resource Record (RR) TypesUpdated
September 2003
- RFC 3655Redefinition of DNS Authenticated Data (AD) bitObsoleted
November 2003
- RFC 3658Delegation Signer (DS) Resource Record (RR)Obsoleted
December 2003
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)Obsoleted
May 2004
- RFC 3757Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) FlagObsoleted
May 2004
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoleted
August 2004
- RFC 4033DNS Security Introduction and RequirementsUpdated
March 2005
- RFC 4034Resource Records for the DNS Security ExtensionsUpdated
March 2005
- RFC 4035Protocol Modifications for the DNS Security ExtensionsUpdated
March 2005
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 2539Storage of Diffie-Hellman Keys in the Domain Name System (DNS)Updated
March 1999
- RFC 2540Detached Domain Name System (DNS) InformationCurrent
March 1999
- RFC 2528Internet X.509 Public Key Infrastructure Representation of Key Exchange Algorithm (KEA) Keys in Internet X.509 Public Key Infrastructure CertificatesCurrent
March 1999
- RFC 2527Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices FrameworkObsoleted
March 1999
- RFC 2510Internet X.509 Public Key Infrastructure Certificate Management ProtocolsObsoleted
March 1999
- RFC 2479Independent Data Unit Protection Generic Security Service Application Program Interface (IDUP-GSS-API)Current
December 1998
- RFC 2459Internet X.509 Public Key Infrastructure Certificate and CRL ProfileObsoleted
January 1999
- RFC 2440OpenPGP Message FormatObsoleted
November 1998
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?