CurrentINTERNET STANDARDIETF streamSTD93

RFC 8945: Secret Key Transaction Authentication for DNS (TSIG)

In plain English — editorial summary, not part of the RFC

This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server. No recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism. This document obsoletes RFCs 2845 and 4635.

Document record

Document ID
RFC8945
Published
November 2020
Authors
F. Dupont; S. Morris; P. Vixie; D. Eastlake 3rd; O. Gudmundsson; B. Wellington
Status
INTERNET STANDARD
Stream
IETF
Area
ops
Pages
22
Also known as
STD93
Obsoletes:
RFC 2845, RFC 4635

Standards lineage

This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.

  1. RFC 2845 (2000)
  2. RFC 4635 (2006)
  3. RFC 8945 (2020)

Read the full history of Secret Key Transaction Authentication for DNS (TSIG)

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/8945-secret-key-transaction-authentication-for-dns-tsig