Last Call: <draft-ietf-tls-dnssec-chain-extension-06.txt> (A DANE Record and DNSSEC Authentication Chain Extension for TLS) to Proposed Standard

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The IESG has received a request from the Transport Layer Security WG (tls) to
consider the following document: - 'A DANE Record and DNSSEC Authentication
Chain Extension for TLS'
  <draft-ietf-tls-dnssec-chain-extension-06.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2018-02-07. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the beginning of
the Subject line to allow automated sorting.

Abstract


   This draft describes a new TLS extension for transport of a DNS
   record set serialized with the DNSSEC signatures needed to
   authenticate that record set.  The intent of this proposal is to
   allow TLS clients to perform DANE authentication of a TLS server
   without needing to perform additional DNS record lookups.  It will
   typically not be used for general DNSSEC validation of TLS endpoint
   names.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-tls-dnssec-chain-extension/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-tls-dnssec-chain-extension/ballot/


No IPR declarations have been submitted directly on this I-D.







[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux