Skip to main content

Automating DNSSEC delegation trust maintenance

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Warren "Ace" Kumari , Ólafur Guðmundsson , George Barwood
Last updated 2013-10-05
Replaced by draft-ietf-dnsop-delegation-trust-maintainance, draft-ietf-dnsop-delegation-trust-maintainance, RFC 7344
RFC stream (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-dnsop-delegation-trust-maintainance, draft-ietf-dnsop-delegation-trust-maintainance
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This document describes a method to allow DNS operators to more easily update DNSSEC Key Signing Keys using DNS as communication channel. This document does not address the initial configuration of trust anchors for a domain. The technique described is aimed at delegations in which it is currently hard to move information from the child to parent.


Warren "Ace" Kumari
Ólafur Guðmundsson
George Barwood

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)