@techreport{kosters-dnsext-dnssec-opt-in-01, number = {draft-kosters-dnsext-dnssec-opt-in-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-kosters-dnsext-dnssec-opt-in/01/}, author = {Mark Kosters}, title = {{DNSSEC Opt-in for Large Zones}}, pagetotal = 9, year = 2001, month = mar, day = 6, abstract = {In order for DNSSEC to be deployed operationally with large zones and little operational impact, there needs to be included a mechanism that allows for the separation of secure versus unsecure views of zones. This needs to be done in a transparent fashion that allows DNSSEC to be deployed in an incremental manner. This document proposes the use of an extended RCODE to signify that a DNSSEC-aware requestor may have to re-query for the information, if and only if, the delegation is not yet secure. Thus, one can maintain two views of the zone and expand the DNSSEC zone as demand warrants.}, }