RFC 7858: Specification for DNS over Transport Layer Security (TLS)
In plain English — editorial summary, not part of the RFC
This document describes the use of Transport Layer Security (TLS) to provide privacy for DNS. Encryption provided by TLS eliminates opportunities for eavesdropping and on-path tampering with DNS queries in the network, such as discussed in RFC 7626. In addition, this document specifies two usage profiles for DNS over TLS and provides advice on performance considerations to minimize overhead from using TCP and TLS with DNS. This document focuses on securing stub-to-recursive traffic, as per the charter of the DPRIVE Working Group. It does not prevent future applications of the protocol to recursive-to-authoritative traffic.
Document record
- Document ID
- RFC7858
- Published
- May 2016
- Authors
- Z. Hu; L. Zhu; J. Heidemann; A. Mankin; D. Wessels; P. Hoffman
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- int
- Pages
- 19
- Also known as
- —
- Updated by:
- RFC 8310
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7856Softwire Mesh Management Information Base (MIB)Current
May 2016
- RFC 7864Proxy Mobile IPv6 Extensions to Support Flow MobilityCurrent
May 2016
- RFC 7847Logical-Interface Support for IP Hosts with Multi-Access SupportCurrent
May 2016
- RFC 7870Dual-Stack Lite (DS-Lite) Management Information Base (MIB) for Address Family Transition Routers (AFTRs)Current
June 2016
- RFC 7844Anonymity Profiles for DHCP ClientsCurrent
May 2016
- RFC 7843Port Control Protocol (PCP) Third-Party ID OptionCurrent
May 2016
- RFC 7839Access-Network-Identifier Option in DHCPCurrent
June 2016
- RFC 7830The EDNS(0) Padding OptionCurrent
May 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?