Message Digest for DNS Zones
draft-wessels-dns-zone-digest-02

Document Type Active Internet-Draft (dnsop WG)
Last updated 2018-07-20 (latest revision 2018-07-02)
Stream IETF
Intended RFC status (None)
Formats plain text xml pdf html bibtex
Stream WG state Candidate for WG Adoption
Document shepherd No shepherd assigned
IESG IESG state I-D Exists
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)
Internet Engineering Task Force                               D. Wessels
Internet-Draft                                                 P. Barber
Intended status: Standards Track                             M. Weinberg
Expires: January 3, 2019                                        Verisign
                                                               W. Kumari
                                                                  Google
                                                             W. Hardaker
                                                                 USC/ISI
                                                            July 2, 2018

                      Message Digest for DNS Zones
                    draft-wessels-dns-zone-digest-02

Abstract

   This document describes a protocol and DNS Resource Record used to
   provide a message digest over DNS zone data.  In particular, it
   describes how to compute, sign, represent, and use the message digest
   to verify the contents of a zone for accuracy and completeness.  The
   ZONEMD Resource Record type is introduced for conveying the message
   digest data.

Status of This Memo

   This Internet-Draft is submitted in full conformance with the
   provisions of BCP 78 and BCP 79.

   Internet-Drafts are working documents of the Internet Engineering
   Task Force (IETF).  Note that other groups may also distribute
   working documents as Internet-Drafts.  The list of current Internet-
   Drafts is at https://datatracker.ietf.org/drafts/current/.

   Internet-Drafts are draft documents valid for a maximum of six months
   and may be updated, replaced, or obsoleted by other documents at any
   time.  It is inappropriate to use Internet-Drafts as reference
   material or to cite them other than as "work in progress."

   This Internet-Draft will expire on January 3, 2019.

Copyright Notice

   Copyright (c) 2018 IETF Trust and the persons identified as the
   document authors.  All rights reserved.

   This document is subject to BCP 78 and the IETF Trust's Legal
   Provisions Relating to IETF Documents
   (https://trustee.ietf.org/license-info) in effect on the date of

Wessels, et al.          Expires January 3, 2019                [Page 1]
Internet-Draft               DNS Zone Digest                   July 2018

   publication of this document.  Please review these documents
   carefully, as they describe your rights and restrictions with respect
   to this document.  Code Components extracted from this document must
   include Simplified BSD License text as described in Section 4.e of
   the Trust Legal Provisions and are provided without warranty as
   described in the Simplified BSD License.

Table of Contents

   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   3
     1.1.  Motivation  . . . . . . . . . . . . . . . . . . . . . . .   3
     1.2.  Design Overview . . . . . . . . . . . . . . . . . . . . .   5
     1.3.  Requirements Language . . . . . . . . . . . . . . . . . .   6
   2.  The ZONEMD Resource Record  . . . . . . . . . . . . . . . . .   6
     2.1.  ZONEMD RDATA Wire Format  . . . . . . . . . . . . . . . .   6
       2.1.1.  The Serial Field  . . . . . . . . . . . . . . . . . .   6
       2.1.2.  The Digest Type Field . . . . . . . . . . . . . . . .   6
       2.1.3.  The Digest Field  . . . . . . . . . . . . . . . . . .   7
     2.2.  ZONEMD Presentation Format  . . . . . . . . . . . . . . .   7
     2.3.  ZONEMD Example  . . . . . . . . . . . . . . . . . . . . .   7
   3.  Calculating the Digest  . . . . . . . . . . . . . . . . . . .   8
     3.1.  Canonical Format and Ordering . . . . . . . . . . . . . .   8
       3.1.1.  Order of RRsets Having the Same Owner Name  . . . . .   8
       3.1.2.  Special Considerations for SOA RRs  . . . . . . . . .   8
     3.2.  Add ZONEMD Placeholder  . . . . . . . . . . . . . . . . .   8
     3.3.  Optionally Sign the Zone  . . . . . . . . . . . . . . . .   9
     3.4.  Calculate the Digest  . . . . . . . . . . . . . . . . . .   9
       3.4.1.  Inclusion/Exclusion Rules . . . . . . . . . . . . . .   9
     3.5.  Update ZONEMD RR  . . . . . . . . . . . . . . . . . . . .  10
   4.  Verifying Zone Message Digest . . . . . . . . . . . . . . . .  10
   5.  IANA Considerations . . . . . . . . . . . . . . . . . . . . .  11
     5.1.  ZONEMD RRtype . . . . . . . . . . . . . . . . . . . . . .  11
     5.2.  ZONEMD Digest Type  . . . . . . . . . . . . . . . . . . .  11
   6.  Security Considerations . . . . . . . . . . . . . . . . . . .  11
     6.1.  Attacks Against the Zone Digest . . . . . . . . . . . . .  11
     6.2.  Attacks Utilizing the Zone Digest . . . . . . . . . . . .  12
   7.  Privacy Considerations  . . . . . . . . . . . . . . . . . . .  12
   8.  Acknowledgments . . . . . . . . . . . . . . . . . . . . . . .  12
   9.  Implementation Status . . . . . . . . . . . . . . . . . . . .  12
     9.1.  Authors' Implementation . . . . . . . . . . . . . . . . .  12
   10. Change Log  . . . . . . . . . . . . . . . . . . . . . . . . .  13
Show full document text