%% You should probably cite draft-ietf-dprive-xfr-over-tls instead of this I-D. @techreport{hzpa-dprive-xfr-over-tls-02, number = {draft-hzpa-dprive-xfr-over-tls-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hzpa-dprive-xfr-over-tls/02/}, author = {Han Zhang and Pallavi Aras and Willem Toorop and Sara Dickinson and Allison Mankin}, title = {{DNS Zone Transfer-over-TLS}}, pagetotal = 18, year = 2019, month = jul, day = 8, abstract = {DNS zone transfers are transmitted in clear text, which gives attackers the opportunity to collect the content of a zone by eavesdropping on network connections. The DNS Transaction Signature (TSIG) mechanism is specified to restrict direct zone transfer to authorized clients only, but it does not add confidentiality. This document specifies use of DNS-over-TLS to prevent zone contents collection via passive monitoring of zone transfers.}, }