RFC 2538 (rfc2538) - Page 1 of 10
Storing Certificates in the Domain Name System (DNS)
Alternative Format: Original Text Document
Network Working Group D. Eastlake
Request for Comments: 2538 IBM
Category: Standards Track O. Gudmundsson
TIS Labs
March 1999
Storing Certificates in the Domain Name System (DNS)
Status of this Memo
This document specifies an Internet standards track protocol for the
Internet community, and requests discussion and suggestions for
improvements. Please refer to the current edition of the "Internet
Official Protocol Standards" (STD 1) for the standardization state
and status of this protocol. Distribution of this memo is unlimited.
Copyright Notice
Copyright (C) The Internet Society (1999). All Rights Reserved.
Abstract
Cryptographic public key are frequently published and their
authenticity demonstrated by certificates. A CERT resource record
(RR) is defined so that such certificates and related certificate
revocation lists can be stored in the Domain Name System (DNS).
Table of Contents
Abstract...................................................1
1. Introduction............................................2
2. The CERT Resource Record................................2
2.1 Certificate Type Values................................3
2.2 Text Representation of CERT RRs........................4
2.3 X.509 OIDs.............................................4
3. Appropriate Owner Names for CERT RRs....................5
3.1 X.509 CERT RR Names....................................5
3.2 PGP CERT RR Names......................................6
4. Performance Considerations..............................6
5. IANA Considerations.....................................7
6. Security Considerations.................................7
References.................................................8
Authors' Addresses.........................................9
Full Copyright Notice.....................................10
Eastlake & Gudmundsson Standards Track



