DNSSEC Trust Anchor Configuration and Maintenance

Document Type Expired Internet-Draft (dnsop WG)
Authors Matt Larson  , Ólafur Guðmundsson 
Last updated 2010-10-23
Replaces draft-larson-dnsop-trust-anchor
Stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state Expired
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document recommends a preferred format for specifying trust anchors in DNSSEC validating security-aware resolvers and describes how such a resolver should initialize trust anchors for use. This document also describes different mechanisms for keeping trust anchors up to date over time.


Matt Larson (mlarson@verisign.com)
Ólafur Guðmundsson (ogud@ogud.com)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)