Skip to main content

Parent-side authoritative DNS records for enhanced delegation
draft-peetterr-dnsop-parent-side-auth-types-01

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Peter van Dijk , Petr Špaček
Last updated 2025-06-13 (Latest revision 2024-12-10)
RFC stream (None)
Intended RFC status (None)
Formats
Additional resources GitHub Repository
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

DNS RR types with numbers in the range 0xFA00-0xFDFF are now included in special treatment like DS RR type specified in [RFC4035]. Authoritative servers, DNSSEC signers, and recursive resolvers need to extend the conditions for DS special handling to also include this range. This means: being authoritative on the parent side of a delegation; being signed by the parent; being provided along with delegations by the parent. DNSSEC validators also need to implement downgrade protection described in Section 5.3.

Authors

Peter van Dijk
Petr Špaček

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)