UpdatedPROPOSED STANDARDIETF stream

RFC 7858: Specification for DNS over Transport Layer Security (TLS)

Still current, but amended. Parts of this document are changed or extended by RFC 8310. Read both.

In plain English — editorial summary, not part of the RFC

This document describes the use of Transport Layer Security (TLS) to provide privacy for DNS. Encryption provided by TLS eliminates opportunities for eavesdropping and on-path tampering with DNS queries in the network, such as discussed in RFC 7626. In addition, this document specifies two usage profiles for DNS over TLS and provides advice on performance considerations to minimize overhead from using TCP and TLS with DNS. This document focuses on securing stub-to-recursive traffic, as per the charter of the DPRIVE Working Group. It does not prevent future applications of the protocol to recursive-to-authoritative traffic.

Document record

Document ID
RFC7858
Published
May 2016
Authors
Z. Hu; L. Zhu; J. Heidemann; A. Mankin; D. Wessels; P. Hoffman
Status
PROPOSED STANDARD
Stream
IETF
Area
int
Pages
19
Also known as
Updated by:
RFC 8310

Topics

Referenced by

One later RFC formally updates or obsoletes part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/7858-specification-for-dns-over-transport-layer-security-tls