RFCs about DNSSEC
50 documents indexed under this keyword
- RFC 3007Secure Domain Name System (DNS) Dynamic UpdateCurrentNovember 2000proposed standard
- RFC 3008Domain Name System Security (DNSSEC) Signing AuthorityObsoletedNovember 2000proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3225Indicating Resolver Support of DNSSECUpdatedDecember 2001proposed standard
- RFC 3226DNSSEC and IPv6 A6 aware server/resolver message size requirementsUpdatedDecember 2001proposed standard
- RFC 3755Legacy Resolver Compatibility for Delegation Signer (DS)ObsoletedMay 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3757Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) FlagObsoletedMay 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 3845DNS Security (DNSSEC) NextSECure (NSEC) RDATA FormatObsoletedAugust 2004proposed standardreplaced by RFC4033, RFC4034, RFC4035
- RFC 4033DNS Security Introduction and RequirementsUpdatedMarch 2005proposed standard
- RFC 4034Resource Records for the DNS Security ExtensionsUpdatedMarch 2005proposed standard
- RFC 4035Protocol Modifications for the DNS Security ExtensionsUpdatedMarch 2005proposed standard
- RFC 4255Using DNS to Securely Publish Secure Shell (SSH) Key FingerprintsCurrentJanuary 2006proposed standard
- RFC 4310Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)ObsoletedDecember 2005proposed standardreplaced by RFC5910
- RFC 4471Derivation of DNS Name Predecessor and SuccessorCurrentSeptember 2006experimental
- RFC 5702Use of SHA-2 Algorithms with RSA in DNSKEY and RRSIG Resource Records for DNSSECUpdatedOctober 2009proposed standard
- RFC 5910Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)CurrentMay 2010proposed standard
- RFC 6014Cryptographic Algorithm Identifier Allocation for DNSSECUpdatedNovember 2010proposed standard
- RFC 6604xNAME RCODE and Status Bits ClarificationCurrentApril 2012proposed standard
- RFC 6698The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSAUpdatedAugust 2012proposed standard
- RFC 6781DNSSEC Operational Practices, Version 2CurrentDecember 2012informational
- RFC 6841A Framework for DNSSEC Policies and DNSSEC Practice StatementsCurrentJanuary 2013informational
- RFC 6844DNS Certification Authority Authorization (CAA) Resource RecordObsoletedJanuary 2013proposed standardreplaced by RFC8659
- RFC 6975Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC)CurrentJuly 2013proposed standard
- RFC 7129Authenticated Denial of Existence in the DNSCurrentFebruary 2014informational
- RFC 7218Adding Acronyms to Simplify Conversations about DNS-Based Authentication of Named Entities (DANE)CurrentApril 2014proposed standard
- RFC 7250Using Raw Public Keys in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)CurrentJune 2014proposed standard
- RFC 7344Automating DNSSEC Delegation Trust MaintenanceUpdatedSeptember 2014proposed standard
- RFC 7646Definition and Use of DNSSEC Negative Trust AnchorsCurrentSeptember 2015informational
- RFC 7828The edns-tcp-keepalive EDNS0 OptionCurrentApril 2016proposed standard
- RFC 7901CHAIN Query Requests in DNSCurrentJune 2016experimental
- RFC 8027DNSSEC Roadblock AvoidanceCurrentNovember 2016best current practice
- RFC 8078Managing DS Records from the Parent via CDS/CDNSKEYUpdatedMarch 2017proposed standard
- RFC 8080Edwards-Curve Digital Security Algorithm (EdDSA) for DNSSECCurrentFebruary 2017proposed standard
- RFC 8145Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)UpdatedApril 2017proposed standard
- RFC 8483Yeti DNS TestbedCurrentOctober 2018informational
- RFC 8509A Root Key Trust Anchor Sentinel for DNSSECCurrentDecember 2018proposed standard
- RFC 8683Additional Deployment Guidelines for NAT64/464XLAT in Operator and Enterprise NetworksCurrentNovember 2019informational
- RFC 8749Moving DNSSEC Lookaside Validation (DLV) to Historic StatusCurrentMarch 2020proposed standard
- RFC 8901Multi-Signer DNSSEC ModelsCurrentSeptember 2020informational
- RFC 8976Message Digest for DNS ZonesCurrentFebruary 2021proposed standard
- RFC 9077NSEC and NSEC3: TTLs and Aggressive UseCurrentJuly 2021proposed standard
- RFC 9276Guidance for NSEC3 Parameter SettingsCurrentAugust 2022best current practice
- RFC 9364DNS Security Extensions (DNSSEC)CurrentFebruary 2023best current practice
- RFC 9615Automatic DNSSEC Bootstrapping Using Authenticated Signals from the Zone's OperatorCurrentJuly 2024proposed standard
- RFC 9726Operational Considerations for Use of DNS in Internet of Things (IoT) DevicesCurrentMarch 2025best current practice
- RFC 9824Compact Denial of Existence in DNSSECCurrentSeptember 2025proposed standard
- RFC 9859Generalized DNS NotificationsCurrentSeptember 2025proposed standard
- RFC 9904DNSSEC Cryptographic Algorithm Recommendation Update ProcessCurrentNovember 2025proposed standard
- RFC 9905Deprecating the Use of SHA-1 in DNSSEC Signature AlgorithmsCurrentNovember 2025proposed standard
- RFC 9906Deprecate Usage of ECC-GOST within DNSSECCurrentNovember 2025proposed standard
- RFC 9975Clarifications on CDS/CDNSKEY and CSYNC ConsistencyCurrentMay 2026proposed standard