<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsop-edns-key-tag" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-edns-key-tag-04">
   <front>
      <title>Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)</title>
      <author initials="D." surname="Wessels" fullname="Duane Wessels">
         </author>
      <author initials="W." surname="Kumari" fullname="Warren Kumari">
         </author>
      <author initials="P. E." surname="Hoffman" fullname="Paul E. Hoffman">
         </author>
      <date month="January" day="17" year="2017" />
      <abstract>
	 <t>   The DNS Security Extensions (DNSSEC) were developed to provide origin
   authentication and integrity protection for DNS data by using digital
   signatures.  These digital signatures can be verified by building a
   chain-of-trust starting from a trust anchor and proceeding down to a
   particular node in the DNS.  This document specifies two different
   ways for validating resolvers to signal to a server which keys are
   referenced in their chain-of-trust (see Section 1.1 for the
   rationale).  The data from such signaling allow zone administrators
   to monitor the progress of rollovers in a DNSSEC-signed zone.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsop-edns-key-tag-04" />
   
</reference>
