DNSSEC/RFC4033について、ここに記述してください。

http://tools.ietf.org/html/rfc4033


DNSSECで守られているはずのゾーンの一部がInsecureだと判断されるとしたら、 DNSSECプロトコルの欠陥である。

本来であれば、そういうことがないことを示すのがRFC提案者の仕事であるが。

Abstract

   The Domain Name System Security Extensions (DNSSEC) add data origin
   authentication and data integrity to the Domain Name System.  This
   document introduces these extensions and describes their capabilities
   and limitations.  This document also discusses the services that the
   DNS security extensions do and do not provide.  Last, this document
   describes the interrelationships between the documents that
   collectively describe DNSSEC.

1. Introduction

   This document introduces the Domain Name System Security Extensions
   (DNSSEC).  This document and its two companion documents ([RFC4034]
   and [RFC4035]) update, clarify, and refine the security extensions
   defined in [RFC2535] and its predecessors.  These security extensions
   consist of a set of new resource record types and modifications to
   the existing DNS protocol ([RFC1035]).  The new records and protocol
   modifications are not fully described in this document, but are
   described in a family of documents outlined in Section 10.  Sections
   3 and 4 describe the capabilities and limitations of the security
   extensions in greater detail.  Section 5 discusses the scope of the
   document set.  Sections 6, 7, 8, and 9 discuss the effect that these
   security extensions will have on resolvers, stub resolvers, zones,
   and name servers.

Sections 3 and 4 describe the capabilities and limitations of the security extensions in greater detail.

2. Definitions of Important DNSSEC Terms

MoinQ: DNSSEC/RFC/4033 (last edited 2024-12-13 03:07:21 by ToshinoriMaeno)