{"draft":"draft-ietf-dnsext-dnssec-online-signing-02","doc_id":"RFC4470","title":"Minimally Covering NSEC Records and DNSSEC On-line Signing","authors":["S. Weiler","J. Ihren"],"format":["ASCII","HTML"],"page_count":"8","pub_status":"PROPOSED STANDARD","status":"PROPOSED STANDARD","source":"DNS Extensions","abstract":"This document describes how to construct DNSSEC NSEC resource records that cover a smaller range of names\r\nthan called for by RFC 4034. By generating and signing these records\r\non demand, authoritative name servers can effectively stop the\r\ndisclosure of zone contents otherwise made possible by walking the\r\nchain of NSEC records in a signed zone. [STANDARDS-TRACK]","pub_date":"April 2006","keywords":["dns security","domain name system"],"obsoletes":[],"obsoleted_by":[],"updates":["RFC4035","RFC4034"],"updated_by":[],"see_also":[],"doi":"10.17487\/RFC4470","errata_url":"https:\/\/www.rfc-editor.org\/errata\/rfc4470"}