Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC)
Author(s) -
Steve Crocker,
Scott Rose
Publication year - 2013
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc6975
Subject(s) - computer science , computer network , cryptography , computer security
The DNS Security Extensions (DNSSEC) were developed to provide originauthentication and integrity protection for DNS data by using digitalsignatures. These digital signatures can be generated using differentalgorithms. This document specifies a way for validating end-systemresolvers to signal to a server which digital signature and hashalgorithms they support. The extensions allow the signaling of newalgorithm uptake in client code to allow zone administrators to knowwhen it is possible to complete an algorithm rollover in a DNSSEC-signed zone.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom