Internet-Draft draft-ietf-dnsop-compact-denial-of-existence-03.txt is now
available. It is a work item of the Domain Name System Operations (DNSOP) WG
of the IETF.
Title: Compact Denial of Existence in DNSSEC
Authors: Shumon Huque
Christian Elmerot
Olafur Gudmundsson
Name: draft-ietf-dnsop-compact-denial-of-existence-03.txt
Pages: 12
Dates: 2024-03-04
Abstract:
This document describes a technique to generate a signed DNS response
on demand for a non-existent name by claiming that the name exists
but doesn't have any data for the queried record type. Such answers
require only one minimal NSEC record, allow online signing servers to
minimize signing operations and response sizes, and prevent zone
content disclosure.
Discussion Venues
This note is to be removed before publishing as an RFC.
Source for this draft and an issue tracker can be found at
https://github.com/shuque/id-dnssec-compact-lies.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-dnsop-compact-denial-of-existence/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-dnsop-compact-denial-of-existence-03.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-dnsop-compact-denial-of-existence-03
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop