Name: draft-stjohns-dnssec-trustupdate-01
Title: Automated Updates of DNSSEC Trust Anchors
State: Active
Authors: Michael StJohns
Group: Individual Submissions (none)
Date: 2004-07-19
This document describes a means for automated, authenticated and authorized
updating of DNSSEC "trust anchors". The method provides protection against
single key compromise of a key in the trust point key set. Based on the
trust established by the presence of a current anchor, other anchors may be
added at the same place in the hierarchy, and, ultimately, supplant the
existing anchor. This mechanism, if adopted, will require changes to
resolver management behavior (but not resolver resolution behavior), and
the addition of a single flag bit to the DNSKEY record.
|
|
|