Title: Indicating Resolver Support of DNSSEC
Author(s): D. Conrad.
Status: PROPOSED STANDARD
Date: Dec 2001
Length: 11548
In order to deploy DNSSEC (Domain Name System Security Extensions) operationally, DNSSEC aware servers should only perform automatic inclusion of DNSSEC RRs when there is an explicit indication that the resolver can understand those RRs. This document proposes the use of a bit in the EDNS0 header to provide that explicit indication and describes the necessary protocol changes to implement that notification.
|
|
|