%% You should probably cite draft-ietf-dprive-start-tls-for-dns instead of this I-D. @techreport{hzhwm-dprive-start-tls-for-dns-02, number = {draft-hzhwm-dprive-start-tls-for-dns-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hzhwm-dprive-start-tls-for-dns/02/}, author = {Zi Hu and Liang Zhu and John Heidemann and Allison Mankin and Duane Wessels and Paul E. Hoffman}, title = {{TLS for DNS: Initiation and Performance Considerations}}, pagetotal = 15, year = 2015, month = apr, day = 15, abstract = {This document offers an approach to initiating TLS for DNS: use of a dedicated DNS-over-TLS port, and fallback to a mechanism for upgrading a DNS-over-TCP connection over the standard port (TCP/53) to a DNS-over-TLS connection. Encryption provided by TLS eliminates opportunities for eavesdropping on DNS queries in the network, such as discussed in RFC 7258. In addition it specifies two usage profiles for DNS-over-TLS. Finally, it provides advice on performance considerations to minimize overheads from using TCP and TLS with DNS, pertaining to both approaches.}, }