Umbra Wiki rfc rfc/RFC7858
Back to wiki

RFC7858 — Specification for DNS over Transport Layer Security (TLS)

provenance: imported · standards: RFC7858

RFC7858: Specification for DNS over Transport Layer Security (TLS)

IETF Request for Comments

Status PROPOSED STANDARD
Publication status PROPOSED STANDARD
Published May 2016
Stream IETF
Obsoletes
Obsoleted by
Updated by RFC8310

Abstract

This document describes the use of Transport Layer Security (TLS) to provide privacy for DNS. Encryption provided by TLS eliminates opportunities for eavesdropping and on-path tampering with DNS queries in the network, such as discussed in RFC 7626. In addition, this document specifies two usage profiles for DNS over TLS and provides advice on performance considerations to minimize overhead from using TCP and TLS with DNS. This document focuses on securing stub-to-recursive traffic, as per the charter of the DPRIVE Working Group. It does not prevent future applications of the protocol to recursive-to-authoritative traffic.

Official sources

  • Info page: https://www.rfc-editor.org/info/rfc7858
  • Full text: https://www.rfc-editor.org/rfc/rfc7858.txt
  • HTML: https://www.rfc-editor.org/rfc/rfc7858.html

Abstract and metadata are reproduced from the public RFC index; the full text is linked, not copied.