{"id":858,"date":"2016-05-19T12:35:22","date_gmt":"2016-05-19T19:35:22","guid":{"rendered":"https:\/\/ant.isi.edu\/blog\/?p=858"},"modified":"2020-10-19T09:51:30","modified_gmt":"2020-10-19T16:51:30","slug":"new-rfc-specification-for-dns-over-transport-layer-security-tls","status":"publish","type":"post","link":"https:\/\/ant.isi.edu\/blog\/?p=858","title":{"rendered":"new RFC &#8220;Specification for DNS over Transport Layer Security (TLS)&#8221;"},"content":{"rendered":"<p>The Internet <a href=\"http:\/\/dx.doi.org\/10.17487\/RFC7858\">RFC-7858, &#8220;Specification for DNS over Transport Layer Security (TLS)&#8221;,<\/a> was just released by the ITEF as a Standards Track document.<\/p>\n<p>From the abstract:<\/p>\n<blockquote><p>This document describes the use of Transport Layer Security (TLS) to&nbsp;provide privacy for DNS. Encryption provided by TLS eliminates&nbsp;opportunities for eavesdropping and on-path tampering with DNS&nbsp;queries in the network, such as discussed in RFC 7626. In addition,&nbsp;this document specifies two usage profiles for DNS over TLS and&nbsp;provides advice on performance considerations to minimize overhead&nbsp;from using TCP and TLS with DNS.<\/p>\n<p>This document focuses on securing stub-to-recursive traffic, as per<br \/>\nthe charter of the DPRIVE Working Group. It does not prevent future&nbsp;applications of the protocol to recursive-to-authoritative traffic.<\/p><\/blockquote>\n<p>This RFC is joint work of&nbsp;Zhi Hu, Liang Zhu, John Heidemann,&nbsp;Allison Mankin, Duane Wessels, and Paul Hoffman, of USC\/ISI, Verisign, ICANN, and independent (at different times). &nbsp;This RFC is one result of our prior paper &#8220;Connection-Oriented DNS to Improve Privacy&nbsp;and Security&#8221;, but also represents the input of the DPRIVE IETF working group (Warren Kumari and Tim Wicinski, chairs), where it is one of a set of RFCs designed to improve DNS privacy.<\/p>\n<p>On to deployments!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Internet RFC-7858, &#8220;Specification for DNS over Transport Layer Security (TLS)&#8221;, was just released by the ITEF as a Standards Track document. From the abstract: This document describes the use of Transport Layer Security (TLS) to&nbsp;provide privacy for DNS. Encryption provided by TLS eliminates&nbsp;opportunities for eavesdropping and on-path tampering with DNS&nbsp;queries in the network, such [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[288,293],"tags":[63,148,146,58,67,8,93,68,147,18,92,57,101],"class_list":["post-858","post","type-post","status-publish","format-standard","hentry","category-announcements","category-in-the-news","tag-dns","tag-icann","tag-ietf","tag-isi","tag-lacrend","tag-lander","tag-privacy","tag-retro-future","tag-rfc","tag-security","tag-tls","tag-usc","tag-verisign"],"_links":{"self":[{"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/posts\/858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=858"}],"version-history":[{"count":4,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/posts\/858\/revisions"}],"predecessor-version":[{"id":1611,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=\/wp\/v2\/posts\/858\/revisions\/1611"}],"wp:attachment":[{"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ant.isi.edu\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}