%% You should probably cite rfc8145 instead of this I-D. @techreport{ietf-dnsop-edns-key-tag-04, number = {draft-ietf-dnsop-edns-key-tag-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-dnsop-edns-key-tag/04/}, author = {Duane Wessels and Warren "Ace" Kumari and Paul E. Hoffman}, title = {{Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)}}, pagetotal = 12, year = 2017, month = jan, day = 17, abstract = {The DNS Security Extensions (DNSSEC) were developed to provide origin authentication and integrity protection for DNS data by using digital signatures. These digital signatures can be verified by building a chain-of-trust starting from a trust anchor and proceeding down to a particular node in the DNS. This document specifies two different ways for validating resolvers to signal to a server which keys are referenced in their chain-of-trust (see Section 1.1 for the rationale). The data from such signaling allow zone administrators to monitor the progress of rollovers in a DNSSEC-signed zone.}, }