%% You should probably cite draft-ietf-dnsop-nsec3-guidance instead of this I-D. @techreport{hardaker-dnsop-nsec3-guidance-03, number = {draft-hardaker-dnsop-nsec3-guidance-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hardaker-dnsop-nsec3-guidance/03/}, author = {Wes Hardaker and Viktor Dukhovni}, title = {{Guidance for NSEC3 parameter settings}}, pagetotal = 7, year = 2021, month = may, day = 6, abstract = {NSEC3 is a DNSSEC mechanism providing proof of non-existence by promising there are no names that exist between two domainnames within a zone. Unlike its counterpart NSEC, NSEC3 avoids directly disclosing the bounding domainname pairs. This document provides guidance on setting NSEC3 parameters based on recent operational deployment experience.}, }