bk99.de entertain the web since 1997

RFC 6698: DANE: Binding TLS keys via DNSSEC

Summary

RFC 6698 introduces TLSA records with which DNSSEC-secured domains name certificates or keys for TLS. DANE partly moves trust decisions into the DNS hierarchy. Additional trust paths increase both options and operational responsibility.

Ideas

  • TLSA links service, port and transport with certificate data.
  • DNSSEC protects the origin of the record.
  • Usage modes determine the relationship to the public PKI.

Remarks

  • RFC 6698 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Validate DNSSEC before every DANE decision.
  • Plan certificate changes with overlapping TLSA data.

References

Read the RFC at the RFC Editor

Search the Web Archive