Specification for DNS over Transport Layer Security (TLS)

Specification for DNS over Transport Layer Security (TLS)
复制标题

DOI:
10.17487/rfc7858
复制
发表时间:
2016-05
期刊:
RFC
影响因子:
--
通讯作者:
Zi Hu;Liang Zhu;John S. Heidemann;A. Mankin;Duane Wessels;Paul E. Hoffman
Zi Hu;Liang Zhu;John S. Heidemann;A. Mankin;Duane Wessels;Paul E. Hoffman
中科院分区:
其他
文献类型:
--
作者:
Zi Hu;Liang Zhu;John S. Heidemann;A. Mankin;Duane Wessels;Paul E. Hoffman

文献摘要

被引文献

相似文献

本文档描述了运输层安全性(TLS)为DNS提供隐私的使用。 TLS提供的加密消除了网络中的DNS查询的窃听和在路上篡改的机会,例如RFC 7626中的讨论。此外,此文档此文档还指定了DNS的两个用法,并提供了有关TLS的DNS的使用,并提供了有关绩效注意事项的建议将TCP和TLS与DNS一起使用。根据DPRIVE工作组的宪章,本文档着重于确保递归流量。它不能阻止该协议将来应用于递归权威流量。
This document describes the use of Transport Layer Security (TLS) to provide privacy for DNS. Encryption provided by TLS eliminates opportunities for eavesdropping and on-path tampering with DNS queries in the network, such as discussed in RFC 7626. In addition, this document specifies two usage profiles for DNS over TLS and provides advice on performance considerations to minimize overhead from using TCP and TLS with DNS. This document focuses on securing stub-to- recursive traffic, as per the charter of the DPRIVE Working Group. It does not prevent future applications of the protocol to recursive-to- authoritative traffic.