<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsind-tsig" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsind-tsig-13">
   <front>
      <title>Secret Key Transaction Authentication for DNS (TSIG)</title>
      <author initials="O." surname="Guðmundsson" fullname="Ólafur Guðmundsson">
         </author>
      <author initials="P. A." surname="Vixie" fullname="Paul A. Vixie">
         </author>
      <author initials="D. E." surname="Eastlake" fullname="Donald E. Eastlake 3rd">
         <organization>IBM</organization>
      </author>
      <author initials="B." surname="Wellington" fullname="Brian Wellington">
         </author>
      <date month="December" day="21" year="1999" />
      <abstract>
	 <t>This protocol allows for transaction level authentication using
shared secrets and one way hashing.  It can be used to authenticate
dynamic updates as coming from an approved client, or to authenticate
responses as coming from an approved recursive name server.
No provision has been made here for distributing the shared secrets;
it is expected that a network administrator will statically configure
name servers and clients using some out of band mechanism such as
sneaker-net until a secure automated mechanism for key distribution
is available.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsind-tsig-13" />
   
</reference>
