Title: Domain Name System KEY (DNSKEY) Resource Record (RR) Secure Entry Point (SEP) Flag
Author(s): O. Kolkman, J. Schlyter, E. Lewis.
Status: PROPOSED STANDARD
Date: May 2004
Length: 16868
Updates: RFC3755, RFC2535
With the Delegation Signer (DS) resource record (RR), the concept of a public key acting as a secure entry point (SEP) has been introduced. During exchanges of public keys with the parent there is a need to differentiate SEP keys from other public keys in the Domain Name System KEY (DNSKEY) resource record set. A flag bit in the DNSKEY RR is defined to indicate that DNSKEY is to be used as a SEP. The flag bit is intended to assist in operational procedures to correctly generate DS resource records, or to indicate what DNSKEYs are intended for static configuration. The flag bit is not to be used in the DNS verification protocol. This document updates RFC2535 and RFC3755.
|
|
|