%% You should probably cite rfc3655 instead of this I-D. @techreport{ietf-dnsext-ad-is-secure-06, number = {draft-ietf-dnsext-ad-is-secure-06}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-dnsext-ad-is-secure/06/}, author = {Ólafur Guðmundsson and Brian Wellington}, title = {{Redefinition of DNS Authenticated Data (AD) bit}}, pagetotal = 8, year = 2002, month = jun, day = 28, abstract = {This document alters the specification defined in RFC 2535. Based on implementation experience, the Authenticated Data (AD) bit in the DNS header is not useful. This document redefines the AD bit such that it is only set if all answers or records proving that no answers exist in the response has been cryptographically verified or otherwise meets the server's local security policy.}, }