Content deleted Content added
Paulehoffman (talk | contribs) m Fix for bad change |
Paulehoffman (talk | contribs) More RFC updates |
||
Line 108:
Next, it may be that there is not a ___domain name named "www.example.com", in which case instead of returning a RRSIG record in the answer, there will be either an NSEC record or an NSEC3 record. These are "next secure" records that allow the resolver to prove that a ___domain name does not exist. The NSEC/NSEC3 records have RRSIG records, which can be verified as above.
Finally, it may be that the "example.com" zone implements DNSSEC, but either the "com" zone or the root zone do not, creating an "island of security" which needs to be validated in some other way. {{as of|2010|7|15}}, deployment of DNSSEC to root is completed.<ref>{{Cite web | url=
====Stub resolvers====
Line 233:
===Deployment at the DNS root===
DNSSEC was first deployed at the root level on July 15, 2010.<ref name="dnssec-status-live">{{cite web|title=
Political issues surrounding signing the root have been a continuous concern, primarily about some central issues:
Line 249:
====Implementation====
On January 25, 2010, the L (ell) root server began serving a ''Deliberately Unvalidatable Root Zone'' (DURZ). The zone uses signatures of a [[SHA-2]] (SHA-256) hash created using the [[RSA (algorithm)|RSA]] algorithm, as defined in
===Deployment at the TLD level===
Line 263:
ISC decommissioned its DLV registry in 2017.<ref>{{Cite web|title=DLV Replaced With Signed Empty Zone - Internet Systems Consortium|url=https://www.isc.org/blogs/dlv-replaced-with-signed-empty-zone/|access-date=2020-06-05|website=isc.org|date=30 September 2017}}</ref> DLV support was deprecated in BIND 9.12 and completely removed from BIND 9.16.<ref>{{Cite web|title=BIND 9.16.0, Stable Branch for 2020 and Beyond - Internet Systems Consortium|url=https://www.isc.org/blogs/bind9.16.0_released/|access-date=2020-06-05|website=isc.org|date=20 February 2020}}</ref> Unbound version 1.5.4 (July 2015) marked DLV as decommissioned in the example configuration and manual page.<ref>{{Cite web|title=Unbound 1.5.4 Changes|url=https://nlnetlabs.nl/projects/unbound/download/#unbound-1-5-4|access-date=2020-06-05|website=NLnet Labs|language=en}}</ref> Knot Resolver and PowerDNS Recursor never implemented DLV.
In March 2020, the [[IETF]] published {{IETF RFC | 8749}}, retiring DLV as a standard and moving RFC 4432 and RFC 5074 to "Historic" status.<ref>{{cite IETF |title=Moving DNSSEC Lookaside Validation (DLV) to Historic Status |rfc=879 |last1=Mekking |first1=W. |author-link1=W. (Matthijs) Mekking |last2=Mahoney |first2=D. |author-link2=Dan Mahoney (computer scientist) |date= March 2020 |publisher=[[Internet Engineering Task Force|IETF]] |access-date= 3 June 2020|doi=10.17487/RFC8749 }}</ref>
===DNSSEC deployment initiative by the U.S. federal government===
|