RFC 7671

E832821

RFC 7671 is an Internet Engineering Task Force (IETF) standard that specifies operational and security guidelines for using DNS-Based Authentication of Named Entities (DANE) with TLS.

All labels observed (1)

Label Occurrences
RFC 7671 canonical 2

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf IETF Request for Comments
Internet standard
aimsTo improve security of TLS authentication using DNSSEC
provide guidance for safe DANE deployment
appliesTo STARTTLS protocols
linked to: STARTTLS

TLS over TCP
application protocols using TLS
area Applications
Security
BCPNumber BCP 188
category Best Current Practice
defines operational guidelines for DANE
security guidelines for DANE
focusesOn TLS server authentication using DNSSEC
use of DANE with TLS
validation of TLSA records
format text
intendedFor TLS service operators
application developers using DANE
operators of DNSSEC-signed zones
security practitioners
language English
obsoletes none
partOf DANE specification family
publishedBy IETF
Internet Engineering Task Force
relatedTo DNSSEC
PKIX
RFC 6698
TLS server identity verification
relatesToProtocol DANE
DNS-Based Authentication of Named Entities
TLS
Transport Layer Security
linked to: TLS
specifies client behavior when processing TLSA records
error handling for DANE validation failures
interaction of DANE with PKIX
operational practices for publishing TLSA records
security considerations for DANE deployments
server behavior when deploying DANE for TLS
use of TLSA records with different certificate usages
standardizes client processing rules for TLSA records
server deployment practices for DANE
status Internet standard
stream IETF
title The DNS-Based Authentication of Named Entities (DANE) Protocol: Updates and Operational Guidance
updates RFC 6698
usesMechanism DNSSEC

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.