7. IANA Considerations
IANA has made the assignments in this section.
In the following sections, "RFC Required" was chosen for TLSA certificate usages and "Specification Required" for selectors and matching types because of the amount of detail that is likely to be needed for implementers to correctly implement new certificate usages as compared to new selectors and matching types.
7.1. TLSA RRtype
This document uses a new DNS RR type, TLSA, whose value (52) was allocated by IANA from the Resource Record (RR) TYPEs subregistry of the Domain Name System (DNS) Parameters registry.
7.2. TLSA Certificate Usages
This document creates a new registry, "TLSA Certificate Usages". The registry policy is "RFC Required". The initial entries in the registry are:
| Value | Short description | Reference |
|---|---|---|
| 0 | CA constraint | RFC 6698 |
| 1 | Service certificate constraint | RFC 6698 |
| 2 | Trust anchor assertion | RFC 6698 |
| 3 | Domain-issued certificate | RFC 6698 |
| 4-254 | Unassigned | |
| 255 | Private use |
Applications to the registry can request specific values that have yet to be assigned.
7.3. TLSA Selectors
This document creates a new registry, "TLSA Selectors". The registry policy is "Specification Required". The initial entries in the registry are:
| Value | Short description | Reference |
|---|---|---|
| 0 | Full certificate | RFC 6698 |
| 1 | SubjectPublicKeyInfo | RFC 6698 |
| 2-254 | Unassigned | |
| 255 | Private use |
Applications to the registry can request specific values that have yet to be assigned.
7.4. TLSA Matching Types
This document creates a new registry, "TLSA Matching Types". The registry policy is "Specification Required". The initial entries in the registry are:
| Value | Short description | Reference |
|---|---|---|
| 0 | No hash used | RFC 6698 |
| 1 | SHA-256 | RFC 6234 |
| 2 | SHA-512 | RFC 6234 |
| 3-254 | Unassigned | |
| 255 | Private use |
Applications to the registry can request specific values that have yet to be assigned.