@techreport{dnsop-dnssec-extension-pkix-01, number = {draft-dnsop-dnssec-extension-pkix-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-dnsop-dnssec-extension-pkix/01/}, author = {Hyeonmin Lee and Taekyoung Kwon}, title = {{DNSSEC Extension by Using PKIX Certificates}}, pagetotal = 11, year = 2023, month = mar, day = 8, abstract = {The Domain Name System Security Extensions (DNSSEC) were standardized a couple of decades ago but it has not been widely deployed. Thus, a vast majority of DNS messages in the real world are still vulnerable to various kinds of integrity attacks like cache poisoning attacks. This document describes a mechanism that extends the current DNSSEC protocol in such a way that guarantees the integrity of DNS messages using PKIX certificates without any dependencies on other entities in the DNS infrastructure.}, }