A New Internet-Draft is available from the on-line Internet-Drafts directories. Title : DNSSEC Validators DHCP Options Author(s) : Daniel Migault Filename : draft-mglt-homenet-dnssec-validator-dhc-options-02.txt Pages : 12 Date : 2013-10-21 Abstract: DNSSEC provides data integrity and authentication for DNSSEC validators. However, without valid trust anchor(s) and an acceptable value for the current time, DNSSEC validation cannot be performed. As a result, there are multiple cases where DNSSEC validation MUST NOT be performed. In addition, this list of exceptions is expected to become larger over time. Considering an increasing number of cases where DNSSEC is disabled adds complexity to the DNSSEC validator implementations and increases the vectors that disable security. This document assumes that DNSSEC adoption by end devices requires that end devices MUST be able to support a DNSSEC validation always set. This MUST be valid today as well as in the future. This document describes DHCP Options to provision the DHCP Client with valid trust anchors and time so DNSSEC validation can be performed. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-mglt-homenet-dnssec-validator-dhc-options There's also a htmlized version available at: http://tools.ietf.org/html/draft-mglt-homenet-dnssec-validator-dhc-options-02 A diff from the previous version is available at: http://www.ietf.org/rfcdiff?url2=draft-mglt-homenet-dnssec-validator-dhc-options-02 Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. Internet-Drafts are also available by anonymous FTP at: ftp://ftp.ietf.org/internet-drafts/ _______________________________________________ I-D-Announce mailing list I-D-Announce@ietf.org https://www.ietf.org/mailman/listinfo/i-d-announce Internet-Draft directories: http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt