Title: Delegation Signer (DS) Resource Record (RR)
Author(s): O. Gudmundsson.
Status: PROPOSED STANDARD
Date: Dec 2003
Length: 42120
Updates: RFC3090, RFC3008, RFC2535, RFC1035
Updated by: RFC3755
The delegation signer (DS) resource record (RR) is inserted at a zone cut (i.e., a delegation point) to indicate that the delegated zone is digitally signed and that the delegated zone recognizes the indicated key as a valid zone key for the delegated zone. The DS RR is a modification to the DNS Security Extensions definition, motivated by operational considerations. The intent is to use this resource record as an explicit statement about the delegation, rather than relying on inference.
This document defines the DS RR, gives examples of how it is used and describes the implications on resolvers. This change is not backwards compatible with RFC2535. This document updates RFC1035, RFC2535, RFC3008 and RFC3090.
|
|
|