Indicating Resolver Support of DNSSEC, December 2001
- Canonical URL:
- File formats:
- PROPOSED STANDARD
- Updated by:
- RFC 4033, RFC 4034, RFC 4035
- D. Conrad
- dnsext (int)
In order to deploy DNSSEC (Domain Name System Security Extensions) operationally, DNSSEC aware servers should only perform automatic inclusion of DNSSEC RRs when there is an explicit indication that the resolver can understand those RRs. This document proposes the use of a bit in the EDNS0 header to provide that explicit indication and describes the necessary protocol changes to implement that notification. [STANDARDS-TRACK]
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 4844.