RFC 8945: Secret Key Transaction Authentication for DNS (TSIG)
In plain English — editorial summary, not part of the RFC
This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server. No recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism. This document obsoletes RFCs 2845 and 4635.
Document record
- Document ID
- RFC8945
- Published
- November 2020
- Authors
- F. Dupont; S. Morris; P. Vixie; D. Eastlake 3rd; O. Gudmundsson; B. Wellington
- Status
- INTERNET STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 22
- Also known as
- STD93
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 2845 (2000)
- RFC 4635 (2006)
- RFC 8945 (2020)
Read the full history of Secret Key Transaction Authentication for DNS (TSIG) →
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8969A Framework for Automating Service and Network Management with YANGCurrent
January 2021
- RFC 8972Simple Two-Way Active Measurement Protocol Optional ExtensionsCurrent
January 2021
- RFC 8976Message Digest for DNS ZonesCurrent
February 2021
- RFC 8914Extended DNS ErrorsCurrent
October 2020
- RFC 8913Two-Way Active Measurement Protocol (TWAMP) YANG Data ModelCurrent
November 2021
- RFC 8977Registration Data Access Protocol (RDAP) Query Parameters for Result Sorting and PagingCurrent
January 2021
- RFC 8912Initial Performance Metrics Registry EntriesCurrent
November 2021
- RFC 8978Reaction of IPv6 Stateless Address Autoconfiguration (SLAAC) to Flash-Renumbering EventsCurrent
March 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?