Skip to main content

RFC 5155 - DNS Security (DNSSEC) Hashed Authenticated Denial of Existence

  • Status: Proposed Standard
  • Published: March 2008
  • Stream: IETF
  • Errata: No Errata

Status of This Memo​

This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited.


Abstract​

The Domain Name System Security (DNSSEC) Extensions introduced the NSEC resource record (RR) for authenticated denial of existence. This document introduces an alternative resource record, NSEC3, which similarly provides authenticated denial of existence. However, it also provides measures against zone enumeration and permits gradual expansion of delegation-centric zones.


Contents​


  • Official RFC: https://www.rfc-editor.org/rfc/rfc5155.txt
  • RFC DataTracker: https://datatracker.ietf.org/doc/html/rfc5155