RFC 6781

DNSSEC Operational Practices, Version 2, December 2012

Canonical URL:
https://www.rfc-editor.org/rfc/rfc6781.txt
File formats:
Plain TextPDF
Status:
INFORMATIONAL
Obsoletes:
RFC 4641
Authors:
O. Kolkman
W. Mekking
R. Gieben
Stream:
IETF
Source:
dnsop (ops)

Cite this RFC: TXT  |  XML

DOI:  10.17487/RFC6781

Discuss this RFC: Send questions or comments to dnsop@ietf.org

Other actions: Find Errata (if any)  |  Submit Errata  |  Find IPR Disclosures from the IETF


Abstract

This document describes a set of practices for operating the DNS with security extensions (DNSSEC). The target audience is zone administrators deploying DNSSEC. The document discusses operational aspects of using keys and signatures in the DNS. It discusses issues of key generation, key storage, signature generation, key rollover, and related policies. This document obsoletes RFC 4641, as it covers more operational ground and gives more up-to-date requirements with respect to key sizes and the DNSSEC operations.


For the definition of Status, see RFC 2026.

For the definition of Stream, see RFC 4844.


Download PDF Reader



Search RFCs
Advanced Search
×