bk99.de entertain the web since 1997

RFC 4033: DNSSEC: Authenticated DNS data

Summary

RFC 4033 introduces DNSSEC and explains the chain of trust, signed answers and validating resolvers. DNSSEC protects data origin, not confidentiality. Key and delegation operations decide its practical reliability.

Ideas

  • Zones sign resource records cryptographically.
  • DS records link the chain of trust across delegations.
  • Validators distinguish between secure, insecure and bogus answers.

Facts

  • RFC 4033 replaces RFC 2535.

Remarks

  • RFC 4033 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Automate signing and monitor expiry times.
  • Test DS changes end to end before key rollovers.

References

Read the RFC at the RFC Editor

Search the Web Archive