查看完整版本: rfc5011-Automated Updates of DNS Security (DNSSEC) Trust Anchors

wimaxing 2008-6-24 23:18

rfc5011-Automated Updates of DNS Security (DNSSEC) Trust Anchors

【资料成文时间】: 2007
【语言】:英文
【页数】:14
【何人(公司)所著】:
【文件格式】: PDF
【文件原名】:Automated Updates of DNS Security (DNSSEC) Trust Anchors
【摘要或目录】:
Table of Contents
1. Introduction ....................................................2
1.1. Compliance Nomenclature ....................................3
2. Theory of Operation .............................................3
2.1. Revocation .................................................4
2.2. Add Hold-Down ..............................................4
2.3. Active Refresh .............................................5
2.4. Resolver Parameters ........................................6
2.4.1. Add Hold-Down Time ..................................6
2.4.2. Remove Hold-Down Time ...............................6
2.4.3. Minimum Trust Anchors per Trust Point ...............6
3. Changes to DNSKEY RDATA Wire Format .............................6
4. State Table .....................................................6
4.1. Events .....................................................7
4.2. States .....................................................7
5. Trust Point Deletion ............................................8
6. Scenarios - Informative .........................................9
6.1. Adding a Trust Anchor ......................................9
6.2. Deleting a Trust Anchor ....................................9
6.3. Key Roll-Over .............................................10
6.4. Active Key Compromised ....................................10
6.5. Stand-by Key Compromised ..................................10
6.6. Trust Point Deletion ......................................10
7. IANA Considerations ............................................11
8. Security Considerations ........................................11
8.1. Key Ownership vs. Acceptance Policy .......................11
8.2. Multiple Key Compromise ...................................12
8.3. Dynamic Updates ...........................................12
9. Normative References ...........................................12
10. Informative References ........................................12
页: [1]
查看完整版本: rfc5011-Automated Updates of DNS Security (DNSSEC) Trust Anchors