<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsop-kskroll-sentinel" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-kskroll-sentinel-12">
   <front>
      <title>A Root Key Trust Anchor Sentinel for DNSSEC</title>
      <author initials="G." surname="Huston" fullname="Geoff Huston">
         <organization>APNIC</organization>
      </author>
      <author initials="J. L. S." surname="Damas" fullname="Joao Luis Silva Damas">
         <organization>APNIC</organization>
      </author>
      <author initials="W." surname="Kumari" fullname="Warren Kumari">
         <organization>Google</organization>
      </author>
      <date month="May" day="3" year="2018" />
      <abstract>
	 <t>   The DNS Security Extensions (DNSSEC) were developed to provide origin
   authentication and integrity protection for DNS data by using digital
   signatures.  These digital signatures can be verified by building a
   chain of trust starting from a trust anchor and proceeding down to a
   particular node in the DNS.  This document specifies a mechanism that
   will allow an end user and third parties to determine the trusted key
   state for the root key of the resolvers that handle that user&#x27;s DNS
   queries.  Note that this method is only applicable for determining
   which keys are in the trust store for the root key.

   There is an example / toy implementation of this at http://www.ksk-
   test.net .

   [ This document is being collaborated on in Github at:
   https://github.com/APNIC-Labs/draft-kskroll-sentinel.  The most
   recent version of the document, open issues, etc should all be
   available here.  The authors (gratefully) accept pull requests.  Text
   in square brackets will be removed before publication. ]

   [ NOTE: This version uses the labels &quot;root-key-sentinel-is-ta-&quot;, and
   &quot;root-key-sentinel-not-ta-&quot;.; older versions of this document used
   &quot;kskroll-sentinel-is-ta-&lt;key-tag&gt;&quot;, &quot;kskroll-sentinel-not-ta-&lt;key-
   tag&gt;&quot;, and before that, &quot;_is-ta-&lt;key-tag&gt;&quot;, &quot;_not-ta-&lt;key-tag&gt;&quot;.
   Also note that the format of the tag-index is now zero-filled
   decimal.  Apologies to those who have begun implementing earlier
   versions of this specification.]

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsop-kskroll-sentinel-12" />
   
</reference>
