DNS-based Authentication of Named Entities

E831086

DNS-based Authentication of Named Entities (DANE) is an Internet security protocol that uses DNSSEC to bind X.509 certificates to domain names, enabling secure TLS connections without relying solely on traditional certificate authorities.

All labels observed (2)

How this entity was disambiguated

Statements (51)

Predicate Object
instanceOf Internet security protocol ⓘ
abbreviation DANE ⓘ
allows domain owners to specify acceptable TLS certificates ⓘ
use of self-signed certificates with DNSSEC-based trust ⓘ
appliesTo HTTPS ⓘ
IMAP ⓘ
POP3 ⓘ
SMTP ⓘ
XMPP ⓘ
certificateUsageModes CA constraint ⓘ
domain-issued certificate ⓘ
service certificate constraint ⓘ
trust anchor assertion ⓘ
complements certificate authority-based validation ⓘ
public key infrastructure ⓘ
definedIn RFC 6698 ⓘ
RFC 7671 ⓘ
RFC 7672 ⓘ
RFC 7673 ⓘ
enables certificate pinning via DNS ⓘ
opportunistic TLS for SMTP ⓘ
verification of TLS server certificates via DNSSEC ⓘ
introduced 2012 ⓘ
operatesAtLayer application layer ⓘ
operatesWith TCP-based services ⓘ
UDP-based services ⓘ
primaryGoal bind X.509 certificates to domain names ⓘ
enable authentication of TLS endpoints via DNSSEC ⓘ
reduce reliance on traditional certificate authorities ⓘ
protects HTTPS connections ⓘ
SMTP over TLS ⓘ
TLS connections ⓘ
protectsAgainst compromise of public certificate authorities ⓘ
man-in-the-middle attacks on TLS ⓘ
recordType TLSA ⓘ
relatedTo CAA DNS records ⓘ
DNS Certification Authority Authorization ⓘ
reliesOn DNSSEC validation by resolvers ⓘ
DNSSEC-signed zones ⓘ
TLSA records at service domain names ⓘ
requires DNSSEC validation on client side or resolver side ⓘ
securityModel DNSSEC-based trust model ⓘ
standardizedBy IETF ⓘ
Internet Engineering Task Force ⓘ
status Proposed Standard ⓘ
uses DNS Security Extensions ⓘ
DNSSEC ⓘ
Domain Name System ⓘ
TLSA resource records ⓘ
Transport Layer Security ⓘ
linked to: TLS

X.509 certificates ⓘ

How these facts were elicited

Referenced by (7)

Full triples — surface form annotated when it differs from this entity's canonical label.

DANE → fullName → DNS-based Authentication of Named Entities ⓘ
RFC 6698 → workingGroup → DNS-based Authentication of Named Entities ⓘ
RFC 6698 → definesProtocol → DNS-Based Authentication of Named Entities ⓘ
linked to: DNS-based Authentication of Named Entities
RFC 7671 → relatesToProtocol → DNS-Based Authentication of Named Entities ⓘ
linked to: DNS-based Authentication of Named Entities
RFC 7218 → relatedToProtocol → DNS-Based Authentication of Named Entities ⓘ
linked to: DNS-based Authentication of Named Entities
RFC 7672 → usesTechnology → DNS-Based Authentication of Named Entities ⓘ
linked to: DNS-based Authentication of Named Entities
RFC 7674 → usesTechnology → DNS-Based Authentication of Named Entities ⓘ
linked to: DNS-based Authentication of Named Entities