A DANE Record and DNSSEC Authentication Chain Extension for TLS
draft-ietf-tls-dnssec-chain-extension-07
Document | Type | Expired Internet-Draft (tls WG) | |
---|---|---|---|
Authors | Melinda Shore , Richard Barnes , Shumon Huque , Willem Toorop | ||
Last updated | 2018-09-22 (latest revision 2018-03-21) | ||
Replaces | draft-shore-tls-dnssec-chain-extension | ||
Stream | IETF | ||
Intended RFC status | Proposed Standard | ||
Formats |
Expired & archived
pdf
htmlized (tools)
htmlized
bibtex
|
||
Reviews | |||
Stream | WG state | WG Document | |
Document shepherd | Joseph Salowey | ||
Shepherd write-up | Show (last changed 2018-01-22) | ||
IESG | IESG state | Expired (IESG: Dead) | |
Consensus Boilerplate | Yes | ||
Telechat date | |||
Responsible AD | Benjamin Kaduk | ||
Send notices to | Joseph Salowey <joe@salowey.net>, shuque@gmail.com | ||
IANA | IANA review state | Version Changed - Review Needed | |
IANA action state | No IANA Actions |
https://www.ietf.org/archive/id/draft-ietf-tls-dnssec-chain-extension-07.txt
Abstract
This draft describes a new TLS extension for transport of a DNS record set serialized with the DNSSEC signatures needed to authenticate that record set. The intent of this proposal is to allow TLS clients to perform DANE authentication of a TLS server without needing to perform additional DNS record lookups. It is not intended to be used to validate the TLS server's address records.
Authors
Melinda Shore
(mshore@fastly.com)
Richard Barnes
(rlb@ipv.sx)
Shumon Huque
(shuque@gmail.com)
Willem Toorop
(willem@nlnetlabs.nl)
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)