Minimally Covering NSEC Records and DNSSEC On-line Signing
draft-weiler-dnsext-dnssec-online-signing-01
| Document | Type | Replaced Internet-Draft (individual) | |
|---|---|---|---|
| Authors | Samuel Weiler , Johan Ihren | ||
| Last updated | 2005-05-12 (Latest revision 2005-02-21) | ||
| Replaced by | RFC 4470 | ||
| Stream | (None) | ||
| Intended RFC status | (None) | ||
| Formats |
Expired & archived
plain text
htmlized
pdfized
bibtex
|
||
| Stream | Stream state | (No stream defined) | |
| Consensus boilerplate | Unknown | ||
| RFC Editor Note | (None) | ||
| IESG | IESG state | Replaced by draft-ietf-dnsext-dnssec-online-signing | |
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
This Internet-Draft is no longer active. A copy of
the expired Internet-Draft can be found at:
https://www.ietf.org/archive/id/draft-weiler-dnsext-dnssec-online-signing-01.txt
https://www.ietf.org/archive/id/draft-weiler-dnsext-dnssec-online-signing-01.txt
Abstract
This document describes how to construct DNSSEC NSEC resource records that cover a smaller range of names than called for by [-records]. By generating and signing these records on demand, authoritative name servers can effectively stop the disclosure of zone contents otherwise made possible by walking the chain of NSEC records in a signed zone.
Authors
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)