RFC 6698: DANE: Binding TLS keys via DNSSEC
Summary
RFC 6698 introduces TLSA records with which DNSSEC-secured domains name certificates or keys for TLS. DANE partly moves trust decisions into the DNS hierarchy. Additional trust paths increase both options and operational responsibility.
Ideas
- TLSA links service, port and transport with certificate data.
- DNSSEC protects the origin of the record.
- Usage modes determine the relationship to the public PKI.
Remarks
- RFC 6698 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Validate DNSSEC before every DANE decision.
- Plan certificate changes with overlapping TLSA data.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.