<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.dukhovni-tls-dnssec-chain" target="https://datatracker.ietf.org/doc/html/draft-dukhovni-tls-dnssec-chain-08">
   <front>
      <title>TLS DNSSEC Chain Extension</title>
      <author initials="V." surname="Dukhovni" fullname="Viktor Dukhovni">
         <organization>Two Sigma</organization>
      </author>
      <author initials="S." surname="Huque" fullname="Shumon Huque">
         <organization>Salesforce</organization>
      </author>
      <author initials="W." surname="Toorop" fullname="Willem Toorop">
         <organization>NLnet Labs</organization>
      </author>
      <author initials="P." surname="Wouters" fullname="Paul Wouters">
         <organization>Aiven</organization>
      </author>
      <author initials="M." surname="Shore" fullname="Melinda Shore">
         <organization>Fastly</organization>
      </author>
      <date month="June" day="10" year="2021" />
      <abstract>
	 <t>This document describes an experimental TLS extension for the in-band transport of the complete set of records that can be validated by DNSSEC and that are needed to perform DNS-Based Authentication of Named Entities (DANE) of a TLS server. This extension obviates the need to perform separate, out-of-band DNS lookups. When the requisite DNS records do not exist, the extension conveys a denial-of-existence proof that can be validated.

 This experimental extension is developed outside the IETF and is published here to guide implementation of the extension and to ensure interoperability among implementations.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-dukhovni-tls-dnssec-chain-08" />
   
</reference>
