RFC 2845: Secret Key Transaction Authentication for DNS (TSIG)
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 8945.
Current document in this lineage: RFC 8945 — Secret Key Transaction Authentication for DNS (TSIG)
In plain English — editorial summary, not part of the RFC
This protocol allows for transaction level authentication using shared secrets and one way hashing. It can be used to authenticate dynamic updates as coming from an approved client, or to authenticate responses as coming from an approved recursive name server. [STANDARDS-TRACK]
Document record
- Document ID
- RFC2845
- Published
- May 2000
- Authors
- P. Vixie; O. Gudmundsson; D. Eastlake 3rd; B. Wellington
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- int
- Pages
- 15
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 2845 (2000)
- RFC 4635 (2006)
- RFC 8945 (2020) ✓
Read the full history of Secret Key Transaction Authentication for DNS (TSIG) →
Referenced by
4 later RFCs formally update or obsolete part of this document.
- RFC 3645Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS (GSS-TSIG)Current
October 2003
- RFC 4635HMAC SHA (Hashed Message Authentication Code, Secure Hash Algorithm) TSIG Algorithm IdentifiersObsoleted
August 2006
- RFC 6895Domain Name System (DNS) IANA ConsiderationsCurrent
April 2013
- RFC 8945Secret Key Transaction Authentication for DNS (TSIG)Current
November 2020
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 2606Reserved Top Level DNS NamesUpdated
June 1999
- RFC 3090DNS Security Extension Clarification on Zone StatusObsoleted
March 2001
- RFC 3197Applicability Statement for DNS MIB ExtensionsCurrent
November 2001
- RFC 2182Selection and Operation of Secondary DNS ServersCurrent
July 1997
- RFC 2181Clarifications to the DNS SpecificationUpdated
July 1997
- RFC 1996A Mechanism for Prompt Notification of Zone Changes (DNS NOTIFY)Current
August 1996
- RFC 1995Incremental Zone Transfer in DNSUpdated
August 1996
- RFC 1982Serial Number ArithmeticCurrent
August 1996
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?