Zum Hauptinhalt springen

7. IANA Considerations

IANA has made the assignments in this section.

In the following sections, "RFC Required" was chosen for TLSA certificate usages and "Specification Required" for selectors and matching types because of the amount of detail that is likely to be needed for implementers to correctly implement new certificate usages as compared to new selectors and matching types.

7.1. TLSA RRtype​

This document uses a new DNS RR type, TLSA, whose value (52) was allocated by IANA from the Resource Record (RR) TYPEs subregistry of the Domain Name System (DNS) Parameters registry.

7.2. TLSA Certificate Usages​

This document creates a new registry, "TLSA Certificate Usages". The registry policy is "RFC Required". The initial entries in the registry are:

ValueShort descriptionReference
0CA constraintRFC 6698
1Service certificate constraintRFC 6698
2Trust anchor assertionRFC 6698
3Domain-issued certificateRFC 6698
4-254Unassigned
255Private use

Applications to the registry can request specific values that have yet to be assigned.

7.3. TLSA Selectors​

This document creates a new registry, "TLSA Selectors". The registry policy is "Specification Required". The initial entries in the registry are:

ValueShort descriptionReference
0Full certificateRFC 6698
1SubjectPublicKeyInfoRFC 6698
2-254Unassigned
255Private use

Applications to the registry can request specific values that have yet to be assigned.

7.4. TLSA Matching Types​

This document creates a new registry, "TLSA Matching Types". The registry policy is "Specification Required". The initial entries in the registry are:

ValueShort descriptionReference
0No hash usedRFC 6698
1SHA-256RFC 6234
2SHA-512RFC 6234
3-254Unassigned
255Private use

Applications to the registry can request specific values that have yet to be assigned.