A new Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Domain Name System Operations Working Group of
the IETF.
Title : Definition and Use of DNSSEC Negative Trust Anchors
Author(s) : P. Ebersman, et al
Filename : draft-ietf-dnsop-negative-trust-anchors
Pages : 18
Date : 2015-07-14
DNS Security Extensions (DNSSEC) is now entering widespread
deployment. However, domain signing tools and processes are not yet
as mature and reliable as those for non-DNSSEC-related domain
administration tools and processes. This document defines Negative
Trust Anchors which can be used to mitigate DNSSEC validation
failures by disabling DNSSEC validation at specified domains.
[RFC Editor: Please remove this before publication. This document is
being stored in github at https://github.com/wkumari/draft-livingood-
dnsop-negative-trust-anchors . Authors accept pull requests, and keep
the latest (edit buffer) versions there, so commenters can follow
along at home.]
A URL for this Internet-Draft is:
Internet-Drafts are also available by anonymous FTP at:
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
- <ftp://ftp.ietf.org/internet-drafts/draft-ietf-dnsop-negative-trust-anchors>
DNSOP mailing list