Skip to main content

DNSSEC Delegation Signature with Canonical Signer Name
draft-dickson-dnsext-ds2-01

Document Type Expired Internet-Draft (individual)
Author Brian Dickson
Last updated 2010-11-08 (Latest revision 2010-10-22)
Stream (None)
Formats
Expired & archived
plain text html xml htmlized pdfized bibtex
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)
This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at:
https://www.ietf.org/archive/id/draft-dickson-dnsext-ds2-01.txt

Abstract

The Domain Name System Security (DNSSEC) Extensions introduced the DS resource record (RR) for authentication of zone delegations. This document introduces an alternative resource record, DS2, which similarly provides authentication of zone delegations. However, DS2 provides a canonical signer name, for zones whose content may be duplicated with multiple owner names. The zone is signed by the canonical signer, and the DS2 record allows for validation using this signer name. Author's Note

Authors

Brian Dickson

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)