<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.hzhwm-start-tls-for-dns" target="https://datatracker.ietf.org/doc/html/draft-hzhwm-start-tls-for-dns-01">
   <front>
      <title>Starting TLS over DNS</title>
      <author initials="Z." surname="Hu" fullname="Zi Hu">
         <organization>USC/Information Sciences</organization>
      </author>
      <author initials="L." surname="Zhu" fullname="Liang Zhu">
         <organization>USC/Information Sciences</organization>
      </author>
      <author initials="J." surname="Heidemann" fullname="John Heidemann">
         <organization>USC/Information Sciences</organization>
      </author>
      <author initials="A." surname="Mankin" fullname="Allison Mankin">
         <organization>Verisign Labs</organization>
      </author>
      <author initials="D." surname="Wessels" fullname="Duane Wessels">
         <organization>Verisign Labs</organization>
      </author>
      <date month="July" day="4" year="2014" />
      <abstract>
	 <t>   This document describes a technique for upgrading a DNS TCP
   connection to use Transport Layer Security (TLS) over standard ports.
   Encryption provided by DNS-over-TLS eliminates opportunities for
   eavesdropping of DNS queries in the network.  The proposed mechanism
   is backwards compatible with clients and servers that are not aware
   of DNS-over-TLS.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-hzhwm-start-tls-for-dns-01" />
   
</reference>
