@techreport{ietf-dnsop-compact-denial-of-existence-05, number = {draft-ietf-dnsop-compact-denial-of-existence-05}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-dnsop-compact-denial-of-existence/05/}, author = {Shumon Huque and Christian Elmerot and Ólafur Guðmundsson}, title = {{Compact Denial of Existence in DNSSEC}}, pagetotal = 13, year = 2024, month = oct, day = 17, abstract = {This document describes a technique to generate a signed DNS response on demand for a non-existent name by claiming that the name exists but doesn't have any data for the queried record type. Such answers require only one minimal NSEC record, allow online signing servers to minimize signing operations and response sizes, and prevent zone content disclosure. This document updates RFC 4034 and 4035.}, }