RFC 4033: DNSSEC: Authenticated DNS data
Summary
RFC 4033 introduces DNSSEC and explains the chain of trust, signed answers and validating resolvers. DNSSEC protects data origin, not confidentiality. Key and delegation operations decide its practical reliability.
Ideas
- Zones sign resource records cryptographically.
- DS records link the chain of trust across delegations.
- Validators distinguish between secure, insecure and bogus answers.
Facts
- RFC 4033 replaces RFC 2535.
Remarks
- RFC 4033 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Automate signing and monitor expiry times.
- Test DS changes end to end before key rollovers.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.