<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsop-negative-trust-anchors" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-negative-trust-anchors-13">
   <front>
      <title>Definition and Use of DNSSEC Negative Trust Anchors</title>
      <author initials="P." surname="Ebersman" fullname="P Ebersman">
         <organization>Comcast</organization>
      </author>
      <author initials="W." surname="Kumari" fullname="Warren Kumari">
         <organization>Google</organization>
      </author>
      <author initials="C." surname="Griffiths" fullname="Chris Griffiths">
         <organization>Nominet</organization>
      </author>
      <author initials="J." surname="Livingood" fullname="Jason Livingood">
         <organization>Comcast</organization>
      </author>
      <author initials="R." surname="Weber" fullname="Ralf Weber">
         <organization>Nominum</organization>
      </author>
      <date month="August" day="24" year="2015" />
      <abstract>
	 <t>DNS Security Extensions (DNSSEC) is now entering widespread deployment.  However, domain signing tools and processes are not yet as mature and reliable as those for non-DNSSEC-related domain administration tools and processes.  This document defines Negative Trust Anchors (NTAs), which can be used to mitigate DNSSEC validation failures by disabling DNSSEC validation at specified domains.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsop-negative-trust-anchors-13" />
   
</reference>
