UpdatedPROPOSED STANDARDIETF stream

RFC 6698: The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

Still current, but amended. Parts of this document are changed or extended by RFC 7218, RFC 7671, RFC 8749. Read both.

In plain English — editorial summary, not part of the RFC

Encrypted communication on the Internet often uses Transport Layer Security (TLS), which depends on third parties to certify the keys used. This document improves on that situation by enabling the administrators of domain names to specify the keys used in that domain's TLS servers. This requires matching improvements in TLS client software, but no change in TLS server software. [STANDARDS-TRACK]

Document record

Document ID
RFC6698
Published
August 2012
Authors
P. Hoffman; J. Schlyter
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
37
Also known as

Topics

Referenced by

3 later RFCs formally update or obsolete part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/6698-the-dns-based-authentication-of-named-entities-dane-transport-layer-security-tls