RFC 8078: Managing DS Records from the Parent via CDS/CDNSKEY
In plain English — editorial summary, not part of the RFC
RFC 7344 specifies how DNS trust can be maintained across key rollovers in-band between parent and child. This document elevates RFC 7344 from Informational to Standards Track. It also adds a method for initial trust setup and removal of a secure entry point. Changing a domain's DNSSEC status can be a complicated matter involving multiple unrelated parties. Some of these parties, such as the DNS operator, might not even be known by all the organizations involved. The inability to disable DNSSEC via in-band signaling is seen as a problem or liability that prevents some DNSSEC adoption at a large scale. This document adds a method for in-band signaling of these DNSSEC status changes. This document describes reasonable policies to ease deployment of the initial acceptance of new secure entry points (DS records). It is preferable that operators collaborate on the transfer or move of a domain. The best method is to perform a Key Signing Key (KSK) plus Zone Signing Key (ZSK) rollover. If that is not possible, the method using an unsigned intermediate state described in this document can be used to move the domain between two parties. This leaves the domain temporarily unsigned and vulnerable to DNS spoofing, but that is preferred over the alternative of validation failures due to a mismatched DS and DNSKEY record.
Document record
- Document ID
- RFC8078
- Published
- March 2017
- Authors
- O. Gudmundsson; P. Wouters
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 10
- Also known as
- —
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8027DNSSEC Roadblock AvoidanceCurrent
November 2016
- RFC 8145Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)Updated
April 2017
- RFC 7901CHAIN Query Requests in DNSCurrent
June 2016
- RFC 7828The edns-tcp-keepalive EDNS0 OptionCurrent
April 2016
- RFC 8509A Root Key Trust Anchor Sentinel for DNSSECCurrent
December 2018
- RFC 7646Definition and Use of DNSSEC Negative Trust AnchorsCurrent
September 2015
- RFC 8683Additional Deployment Guidelines for NAT64/464XLAT in Operator and Enterprise NetworksCurrent
November 2019
- RFC 8749Moving DNSSEC Lookaside Validation (DLV) to Historic StatusCurrent
March 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?