@techreport{zhang-trans-ct-dnssec-03, number = {draft-zhang-trans-ct-dnssec-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-zhang-trans-ct-dnssec/03/}, author = {Dacheng Zhang and Daniel Kahn Gillmor and ana.hedanping@huawei.com and Behcet Sarikaya and Ning Kong}, title = {{Certificate Transparency for Domain Name System Security Extensions}}, pagetotal = 14, year = 2015, month = jul, day = 5, abstract = {In draft-ietf-trans-rfc6962-bis, a solution (Certificate Transparency) is proposed for publicly logging the existence of Transport Layer Security (TLS) certificates using Merkle Hash Trees. This document proposes a mechanism to extend Certificate Transparency for DNSSEC which publicly logs the DS RRs to notice the issuance of suspect key signing keys.}, }