Domain Name System Security (dnssec)

This Working Group Did Not Meet

NOTE: This charter is a snapshot of the 46th IETF Meeting in Washington, DC. It may now be out-of-date. Last Modified: 05-Mar-99

Chair(s):

James Galvin <galvin@elistx.com>

Security Area Director(s):

Jeffrey Schiller <jis@mit.edu>
Marcus Leech <mleech@nortel.ca>

Security Area Advisor:

Jeffrey Schiller <jis@mit.edu>

Mailing Lists:

General Discussion:dns-security@lists.tislabs.com
To Subscribe: dns-security-request@lists.tislabs.com
Archive: ftp://ftp.tis.com/pub/lists/dns-security

Description of Working Group:

The Domain Name System Security Working Group (DNSSEC) will ensure enhancements to the secure DNS protocol to protect the dynamic update operation of the DNS. Specifically, it must be possible to detect the replay of update transactions and it must be possible to order update transactions. Clock synchronization should be addressed as well as all of the dynamic update specification.

Some of the issues to be explored and resolved include

o scope of creation, deletion, and updates for both names and zones

o protection of names subject to dynamic update during zone transfer

o scope of KEY resource record for more specific names in wildcard scope

o use of or relationship with proposed expiration resource record

One essential assumption has been identified: data in the DNS is considered public information. This assumption means that discussions and proposals involving data confidentiality and access control are explicitly outside the scope of this working group.

Goals and Milestones:

Done

  

Submit proposal for adding Security enhancements to DNS as an Internet-Draft.

Done

  

Update Internet-Draft on adding security enhancements to DNS.

Apr 96

  

Submit Internet-Draft on Secure Dynamic Update

Aug 96

  

Update Internet-Draft on Secure Dynamic Update.

Dec 96

  

Submit Internet-Draft on ensuring security of dynamic update of DNS to IESG for consideration as a Proposed Standard.

Internet-Drafts:

Request For Comments:

RFC

Status

Title

 

RFC2137

PS

Secure Domain Name System Dynamic Update

RFC2535

PS

Domain Name System Security Extensions

RFC2536

PS

DSA KEYs and SIGs in the Domain Name System (DNS)

RFC2537

PS

RSA/MD5 KEYs and SIGs in the Domain Name System (DNS)

RFC2538

PS

Storing Certificates in the Domain Name System (DNS)

RFC2539

PS

Storage of Diffie-Hellman Keys in the Domain Name System (DNS)

RFC2540

E

Detached Domain Name System (DNS) Information

RFC2541

 

DNS Operational Security Considerations