DNSEXT WG Last Call: AD is Secure

Olafur Gudmundsson <ogud@ogud.com> Tue, 13 March 2001 17:14 UTC

Received: from psg.com (exim@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with SMTP id MAA24085 for <dnsext-archive@lists.ietf.org>; Tue, 13 Mar 2001 12:14:20 -0500 (EST)
Received: from lserv by psg.com with local (Exim 3.16 #1) id 14crsO-0008Q6-00 for namedroppers-data@psg.com; Tue, 13 Mar 2001 08:42:24 -0800
Received: from rip.psg.com ([147.28.0.39] ident=exim) by psg.com with esmtp (Exim 3.16 #1) id 14crsN-0008Q0-00 for namedroppers@ops.ietf.org; Tue, 13 Mar 2001 08:42:23 -0800
Received: from randy by rip.psg.com with local (Exim 3.16 #1) id 14crsN-000NUO-00 for namedroppers@ops.ietf.org; Tue, 13 Mar 2001 08:42:23 -0800
Message-Id: <5.0.2.1.0.20010313113429.0324e540@gatt.dc.ogud.com>
X-Sender: post@gatt.dc.ogud.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 13 Mar 2001 11:35:03 -0500
To: namedroppers@ops.ietf.org
From: Olafur Gudmundsson <ogud@ogud.com>
Subject: DNSEXT WG Last Call: AD is Secure
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk

This document clarifies/updates certain sections of RFC2535
redefines/restricts the use of the AD bit in DNS header to be only set
when server has cryptographically verified the answer.
The reason for this is to make allow clients to take advantage of
server that is willing to perform cryptographic checks for client.

This WG last call ends March 29'th 2001.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-dnsext-ad-is-secure-01.txt

This draft is on standards track, if you disagree with that please state why
in your response.

          Olafur



to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.