@techreport{reddy-add-delegated-credentials-03, number = {draft-reddy-add-delegated-credentials-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-reddy-add-delegated-credentials/03/}, author = {Tirumaleswar Reddy.K and Mohamed Boucadair and Dan Wing and Shashank Jain}, title = {{Delegated Credentials to Host Encrypted DNS Forwarders on CPEs}}, pagetotal = 15, year = 2023, month = dec, day = 1, abstract = {An encrypted DNS server is authenticated by a certificate signed by a Certificate Authority (CA). However, for typical encrypted DNS server deployments on Customer Premise Equipment (CPEs), the signature cannot be obtained or requires excessive interactions with a Certificate Authority. This document explores the use of TLS delegated credentials for a DNS server deployed on a CPE. This approach is meant to ease operating DNS forwarders in CPEs while allowing to make use of encrypted DNS capabilities.}, }