Skip to main content

Using DNSSEC Authentication of Named Entities (DANE) with DNS Service Bindings (SVCB) and QUIC
draft-ietf-dnsop-svcb-dane-05

Document Type Expired Internet-Draft (dnsop WG)
Expired & archived
Authors Benjamin M. Schwartz , Robert Evans
Last updated 2025-09-04 (Latest revision 2025-03-03)
Replaces draft-rebs-dnsop-svcb-dane
RFC stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Formats
Reviews
Additional resources GitHub Repository
Mailing list discussion
Stream WG state WG Document
Document shepherd (None)
IESG IESG state Expired
Consensus boilerplate Unknown
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Service Binding (SVCB) records introduce a new form of name indirection in DNS. They also convey information about the endpoint's supported protocols, such as whether QUIC transport is available. This document specifies how DNS-Based Authentication of Named Entities (DANE) interacts with Service Bindings to secure connections, including use of port numbers and transport protocols discovered via SVCB queries. The "_quic" transport name label is introduced to distinguish TLSA records for DTLS and QUIC.

Authors

Benjamin M. Schwartz
Robert Evans

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)