RFC 4635: HMAC SHA (Hashed Message Authentication Code, Secure Hash Algorithm) TSIG Algorithm Identifiers
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 8945.
Current document in this lineage: RFC 8945 — Secret Key Transaction Authentication for DNS (TSIG)
In plain English — editorial summary, not part of the RFC
Use of the Domain Name System TSIG resource record requires specification of a cryptographic message authentication code. Currently, identifiers have been specified only for HMAC MD5 (Hashed Message Authentication Code, Message Digest 5) and GSS (Generic Security Service) TSIG algorithms. This document standardizes identifiers and implementation requirements for additional HMAC SHA (Secure Hash Algorithm) TSIG algorithms and standardizes how to specify and handle the truncation of HMAC values in TSIG. [STANDARDS-TRACK]
Document record
- Document ID
- RFC4635
- Published
- August 2006
- Authors
- D. Eastlake 3rd
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- int
- Pages
- 8
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 2845 (2000)
- RFC 4635 (2006)
- RFC 8945 (2020) ✓
Read the full history of Secret Key Transaction Authentication for DNS (TSIG) →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoleted
August 2004
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)Obsoleted
May 2004
- RFC 3597Handling of Unknown DNS Resource Record (RR) TypesUpdated
September 2003
- RFC 3123A DNS RR Type for Lists of Address Prefixes (APL RR)Current
June 2001
- RFC 3404Dynamic Delegation Discovery System (DDDS) Part Four: The Uniform Resource Identifiers (URI)Current
October 2002
- RFC 3403Dynamic Delegation Discovery System (DDDS) Part Three: The Domain Name System (DNS) DatabaseCurrent
October 2002
- RFC 3402Dynamic Delegation Discovery System (DDDS) Part Two: The AlgorithmCurrent
October 2002
- RFC 2930Secret Key Establishment for DNS (TKEY RR)Updated
September 2000
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?