Connected: An Internet Encyclopedia
RFC 2137

Up: Connected: An Internet Encyclopedia
Up: Requests For Comments
Next: 1. Introduction

RFC 2137

RFC 2137

Network Working Group
Request for Comments: 2137
Updates: 1035
Category: Standards Track

D. Eastlake 3rd
CyberCash, Inc.
April 1997

Secure Domain Name System Dynamic Update

Status of this Memo

This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited.


Domain Name System (DNS) protocol extensions have been defined to authenticate the data in DNS and provide key distribution services [RFC2065]. DNS Dynamic Update operations have also been defined [RFC2136], but without a detailed description of security for the update operation. This memo describes how to use DNSSEC digital signatures covering requests and data to secure updates and restrict updates to those authorized to perform them as indicated by the updater's possession of cryptographic keys.


The contributions of the following persons (who are listed in alphabetic order) to this memo are gratefully acknowledged:

         Olafur Gudmundsson (>
         Charlie Kaufman <>
         Stuart Kwan <>
         Edward Lewis <>

Table of Contents

Next: 1. Introduction

Connected: An Internet Encyclopedia
RFC 2137