[DNSSEC-Transparency] DNSSEC chain wire format

Linus Nordberg linus at nordu.net
Mon Feb 1 18:09:57 CET 2016


We want the log to store not only DS RRs but also all keys (DNSKEY) and
signatures (RRSIG) needed to verify the issuer of the DS.

We want to require that submissions include this chain so that the log
doesn't have to chase them.

What's a good wire format for such a chain?

