DNS-based Authentication of Named Entities

E831086

DNS-based Authentication of Named Entities (DANE) is an Internet security protocol that uses DNSSEC to bind X.509 certificates to domain names, enabling secure TLS connections without relying solely on traditional certificate authorities.

All labels observed (2)

How this entity was disambiguated

Statements (51)

Predicate Object
instanceOf Internet security protocol
abbreviation DANE
allows domain owners to specify acceptable TLS certificates
use of self-signed certificates with DNSSEC-based trust
appliesTo HTTPS
IMAP
POP3
SMTP
XMPP
certificateUsageModes CA constraint
domain-issued certificate
service certificate constraint
trust anchor assertion
complements certificate authority-based validation
public key infrastructure
definedIn RFC 6698
RFC 7671
RFC 7672
RFC 7673
enables certificate pinning via DNS
opportunistic TLS for SMTP
verification of TLS server certificates via DNSSEC
introduced 2012
operatesAtLayer application layer
operatesWith TCP-based services
UDP-based services
primaryGoal bind X.509 certificates to domain names
enable authentication of TLS endpoints via DNSSEC
reduce reliance on traditional certificate authorities
protects HTTPS connections
SMTP over TLS
TLS connections
protectsAgainst compromise of public certificate authorities
man-in-the-middle attacks on TLS
recordType TLSA
relatedTo CAA DNS records
DNS Certification Authority Authorization
reliesOn DNSSEC validation by resolvers
DNSSEC-signed zones
TLSA records at service domain names
requires DNSSEC validation on client side or resolver side
securityModel DNSSEC-based trust model
standardizedBy IETF
Internet Engineering Task Force
status Proposed Standard
uses DNS Security Extensions
DNSSEC
Domain Name System
TLSA resource records
Transport Layer Security
linked to: TLS

X.509 certificates

How these facts were elicited

Referenced by (7)

Full triples — surface form annotated when it differs from this entity's canonical label.

DANE fullName DNS-based Authentication of Named Entities
RFC 6698 workingGroup DNS-based Authentication of Named Entities
RFC 6698 definesProtocol DNS-Based Authentication of Named Entities
linked to: DNS-based Authentication of Named Entities
RFC 7671 relatesToProtocol DNS-Based Authentication of Named Entities
linked to: DNS-based Authentication of Named Entities
RFC 7218 relatedToProtocol DNS-Based Authentication of Named Entities
linked to: DNS-based Authentication of Named Entities
RFC 7672 usesTechnology DNS-Based Authentication of Named Entities
linked to: DNS-based Authentication of Named Entities
RFC 7674 usesTechnology DNS-Based Authentication of Named Entities
linked to: DNS-based Authentication of Named Entities