Automated (DNSSEC) Child Parent Synchronization using DNS UPDATE

Document Type Expired Internet-Draft (individual)
Author Matthijs Mekking 
Last updated 2010-12-21
Stream (None)
Intended RFC status (None)
Expired & archived
pdf htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document proposes a way to synchronise existing trust anchors automatically between a child zone and its parent. The protocol can be used for other Resource Records that are required to delegate from a parent to a child such as NS and glue records. The synchronization allows for a third party to be involved, thus the protocol is suitable for both cases, whether you have to communicate to the registry or to the registrar.


Matthijs Mekking (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)