Skip to main content

DNS Zone Transfer over TLS
RFC 9103

Revision differences

Document history

Date By Action
2021-08-23
(System)
Received changes through RFC Editor sync (created alias RFC 9103, changed title to 'DNS Zone Transfer over TLS', changed abstract to 'DNS zone transfers …
Received changes through RFC Editor sync (created alias RFC 9103, changed title to 'DNS Zone Transfer over TLS', changed abstract to 'DNS zone transfers are transmitted in cleartext, which gives attackers the opportunity to collect the content of a zone by eavesdropping on network connections.  The DNS Transaction Signature (TSIG) mechanism is specified to restrict direct zone transfer to authorized clients only, but it does not add confidentiality.  This document specifies the use of TLS, rather than cleartext, to prevent zone content collection via passive monitoring of zone transfers: XFR over TLS (XoT).  Additionally, this specification updates RFC 1995 and RFC 5936 with respect to efficient use of TCP connections and RFC 7766 with respect to the recommended number of connections between a client and server for each transport.', changed pages to 32, changed standardization level to Proposed Standard, changed state to RFC, added RFC published event at 2021-08-23, changed IESG state to RFC Published, created updates relation between draft-ietf-dprive-xfr-over-tls and RFC 1995, created updates relation between draft-ietf-dprive-xfr-over-tls and RFC 5936, created updates relation between draft-ietf-dprive-xfr-over-tls and RFC 7766)
2021-08-23
(System) RFC published