NSEC3PARAM

E746789

NSEC3PARAM is a DNSSEC resource record that specifies the parameters used for NSEC3 hashing, enabling more secure and privacy-preserving denial-of-existence proofs in DNS.

All labels observed (1)

Label Occurrences
NSEC3PARAM canonical 1

How this entity was disambiguated

Statements (44)

Predicate Object
instanceOf DNS resource record ⓘ
DNSSEC resource record type ⓘ
affects NSEC3 records in the zone ⓘ
appearsIn zone apex authoritative data ⓘ
category security ⓘ
controls NSEC3 hash parameters for a zone ⓘ
definedInRFC RFC 5155 ⓘ
flagsBit0Meaning Opt-Out ⓘ
flagsFieldType 8-bit unsigned integer ⓘ
hasField Flags ⓘ
Hash Algorithm ⓘ
Iterations ⓘ
Salt ⓘ
Salt Length ⓘ
hashAlgorithmDefault SHA-1 ⓘ
hashAlgorithmFieldType 8-bit unsigned integer ⓘ
hashAlgorithmRegistry IANA DNSSEC NSEC3 Hash Algorithm Registry ⓘ
hasMnemonic NSEC3PARAM ⓘ
hasPurpose improve privacy of DNSSEC negative responses ⓘ
specify parameters for NSEC3 hashing ⓘ
support authenticated denial of existence ⓘ
improvesOver NSEC ⓘ
iterationsFieldType 16-bit unsigned integer ⓘ
iterationsPurpose increase cost of dictionary attacks ⓘ
mustBeSigned true ⓘ
negativeResponseType authenticated denial of existence of names ⓘ
authenticated denial of existence of types at an existing name ⓘ
ownerNameScope zone apex ⓘ
privacyProperty prevents simple zone walking ⓘ
processedBy authoritative DNS servers ⓘ
validating resolvers ⓘ
recordClass IN ⓘ
relatedTo NSEC3 ⓘ
saltFieldType variable-length octet string ⓘ
saltLengthFieldType 8-bit unsigned integer ⓘ
saltPurpose defend against precomputed hash attacks ⓘ
status Standard ⓘ
supportsOptOut true ⓘ
tag NSEC3PARAM ⓘ
usedFor authenticated denial of existence of DNS names ⓘ
negative DNSSEC responses ⓘ
usedIn DNSSEC ⓘ
usedWith signed DNS zones ⓘ
wireFormatDefinedIn RFC 5155 Section 3.2 ⓘ
linked to: RFC 5155

How these facts were elicited

Referenced by (1)

Full triples — surface form annotated when it differs from this entity's canonical label.

RFC 5155 → definesExtension → NSEC3PARAM ⓘ