Skip to main content

DNSSEC Delegation Signature with Canonical Signer Name
draft-dickson-dnsext-ds2-01

Document Type Expired Internet-Draft (individual)
Expired & archived
Author Brian Dickson
Last updated 2010-11-08
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

The Domain Name System Security (DNSSEC) Extensions introduced the DS resource record (RR) for authentication of zone delegations. This document introduces an alternative resource record, DS2, which similarly provides authentication of zone delegations. However, DS2 provides a canonical signer name, for zones whose content may be duplicated with multiple owner names. The zone is signed by the canonical signer, and the DS2 record allows for validation using this signer name. Author's Note

Authors

Brian Dickson

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)