[DNSSEC-Transparency] DNSSEC chain wire format
paul at nohats.ca
Mon Feb 1 19:30:54 CET 2016
Dns binary format similar to draft-dnsops-edns-query-chain.
The stock dns libraries can be used.
This is also the format the new TLS dnssec extension will use.
Sent from my iPhone
> On Feb 1, 2016, at 18:09, Linus Nordberg <linus at nordu.net> wrote:
> We want the log to store not only DS RRs but also all keys (DNSKEY) and
> signatures (RRSIG) needed to verify the issuer of the DS.
> We want to require that submissions include this chain so that the log
> doesn't have to chase them.
> What's a good wire format for such a chain?
> DNSSEC-Transparency mailing list
> DNSSEC-Transparency at lists.sunet.se
More information about the DNSSEC-Transparency