Copyright © 2005 The Institute of Electronics, Information and Communication Engineers
Special Section on Internet Technology V -- Papers |
Preventing Child Neglect in DNSSECbis Using Lookaside Validation (DLV)*
1 The author is with Internet Systems Consortium, Redwood City, CA 940633110, USA. E-mail: vixie{at}isc.org
The DNSSECbis data model has key introduction follow the delegation chain, thus requiring a zone's parent to become secure before a zone itself can be secured. Ultimately this leads to non-deployability since the root zone will probably not be secured any time soon. We describe an early deployment aid for DNSSECbis whereby key introduction can be done via cooperating third parties.
Key Words: DNS, domain name system, DNS security, DNSSEC, secure DNS, Internet
Manuscript received October 5, 2004.