RFC 5011

E206332

RFC 5011 is an Internet standard that specifies automated trust anchor rollover mechanisms for DNSSEC to simplify and secure key management in the Domain Name System.

All labels observed (1)

Label Occurrences
RFC 5011 canonical 2

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf DNSSEC specification ⓘ
Internet standard ⓘ
Request for Comments ⓘ
aimsTo improve security of DNSSEC key management ⓘ
simplify DNSSEC trust anchor maintenance ⓘ
appliesTo DNS resolvers ⓘ
DNS validating resolvers ⓘ
Domain Name System Security Extensions ⓘ
linked to: DNSSEC
area Security ⓘ
assumes initially configured trust anchor ⓘ
category Standards Track ⓘ
defines automated trust anchor rollover for DNSSEC ⓘ
definesConcept add-hold-down time ⓘ
hold-down timer ⓘ
remove-hold-down time ⓘ
revocation of trust anchors ⓘ
trust anchor ⓘ
documentType Technical specification ⓘ
enables in-band trust anchor updates ⓘ
focusesOn key rollover automation ⓘ
trust anchor management ⓘ
hasKeyword DNSSEC ⓘ
key rollover ⓘ
trust anchor ⓘ
hasProtocolNumber none ⓘ
identifier RFC 5011 ⓘ
intendedFor DNSSEC implementers ⓘ
operators of DNS validating resolvers ⓘ
isPartOf DNSSEC standards ⓘ
language English ⓘ
obsoletedBy none ⓘ
obsoletes none ⓘ
publicationMonth September ⓘ
publicationYear 2007 ⓘ
publishedBy Internet Engineering Task Force ⓘ
publishedInSeries RFC Series ⓘ
linked to: RFCs
relatedTo DNS root key rollover ⓘ
DNSSEC ⓘ
requires persistent storage of trust anchors ⓘ
tracking of key timing metadata ⓘ
specifies mechanisms for automated addition of trust anchors ⓘ
mechanisms for automated replacement of trust anchors ⓘ
mechanisms for automated revocation of trust anchors ⓘ
standardizes behavior of validating resolvers during key rollover ⓘ
status Proposed Standard ⓘ
title Automated Updates of DNS Security (DNSSEC) Trust Anchors ⓘ
updatesMechanismOf DNSSEC trust anchor configuration ⓘ
uses DNSKEY resource records ⓘ
RRSIG resource records ⓘ

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.

DNSSEC → definedInRFC → RFC 5011 ⓘ
RFC 5011 → identifier → RFC 5011 ⓘ