RFC 4641: DNSSEC Operational Practices
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 6781.
Current document in this lineage: RFC 6781 — DNSSEC Operational Practices, Version 2
In plain English — editorial summary, not part of the RFC
This document describes a set of practices for operating the DNS with security extensions (DNSSEC). The target audience is zone administrators deploying DNSSEC. The document discusses operational aspects of using keys and signatures in the DNS. It discusses issues of key generation, key storage, signature generation, key rollover, and related policies. This document obsoletes RFC 2541, as it covers more operational ground and gives more up-to-date requirements with respect to key sizes and the new DNSSEC specification. This memo provides information for the Internet community.
Document record
- Document ID
- RFC4641
- Published
- September 2006
- Authors
- O. Kolkman; R. Gieben
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 35
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 2541 (1999)
- RFC 4641 (2006)
- RFC 6781 (2012) ✓
Read the full history of DNSSEC Operational Practices, Version 2 →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 3110RSA/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS)Updated
May 2001
- RFC 4431The DNSSEC Lookaside Validation (DLV) DNS Resource RecordCurrent
February 2006
- RFC 4322Opportunistic Encryption using the Internet Key Exchange (IKE)Current
December 2005
- RFC 3364Tradeoffs in Domain Name System (DNS) Support for Internet Protocol version 6 (IPv6)Current
August 2002
- RFC 2929Domain Name System (DNS) IANA ConsiderationsObsoleted
September 2000
- RFC 2672Non-Terminal DNS Name RedirectionObsoleted
August 1999
- RFC 10029DNS Multiple QTYPEsCurrent
July 2026
- RFC 4074Common Misbehavior Against DNS Queries for IPv6 AddressesCurrent
June 2005
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?