RFC 9975: Clarifications on CDS/CDNSKEY and CSYNC Consistency
In plain English — editorial summary, not part of the RFC
Maintenance of DNS delegations requires occasional changes of the DS and NS record sets on the parent side of the delegation. For the case of DS records, "Automating DNSSEC Delegation Trust Maintenance" (RFC 7344) provides automation by allowing the child to publish CDS and/or CDNSKEY records holding the prospective DS parameters that the parent can ingest. Similarly, "Child-to-Parent Synchronization in DNS" (RFC 7477) specifies CSYNC records to indicate a desired update of the delegation's NS (and glue) records. Parent-side entities (e.g., Registries and Registrars) can query these records from the child and, after validation, use them to update the parent-side Resource Record Sets (RRsets) of the delegation. This document specifies under which conditions the target states expressed via CDS/CDNSKEY and CSYNC records are considered "consistent". Parent-side entities accepting such records from the child have to ensure that update requests retrieved from different authoritative nameservers satisfy these consistency requirements before taking any action based on them. This document updates RFCs 7344 and 7477.
Document record
- Document ID
- RFC9975
- Published
- May 2026
- Authors
- P. Thomassen
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- ops
- Pages
- 16
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9615Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's OperatorCurrent
July 2024
- RFC 9859Generalized DNS NotificationsCurrent
September 2025
- RFC 5910Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)Current
May 2010
- RFC 10026Operational Recommendations for DNSSEC Delegation Signer (DS) AutomationCurrent
July 2026
- RFC 9907Guidelines for Authors and Reviewers of Documents Containing YANG Data ModelsCurrent
March 2026
- RFC 9906Deprecate Usage of ECC-GOST within DNSSECCurrent
November 2025
- RFC 9905Deprecating the Use of SHA-1 in DNSSEC Signature AlgorithmsCurrent
November 2025
- RFC 9904DNSSEC Cryptographic Algorithm Recommendation Update ProcessCurrent
November 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?