{
  "number": 8945,
  "title": "Secret Key Transaction Authentication for DNS (TSIG)",
  "authors": [
    "F. Dupont",
    "S. Morris",
    "P. Vixie",
    "D. Eastlake 3rd",
    "O. Gudmundsson",
    "B. Wellington"
  ],
  "published": "2020-11",
  "status": "Internet Standard",
  "stream": "IETF",
  "area": "ops",
  "working_group": "dnsop",
  "pages": 22,
  "formats": [
    "HTML",
    "TXT",
    "PDF",
    "XML"
  ],
  "abstract": "This document describes a protocol for transaction-level authentication using shared secrets and one-way hashing. It can be used to authenticate dynamic updates to a DNS zone as coming from an approved client or to authenticate responses as coming from an approved name server.\n\nNo recommendation is made here for distributing the shared secrets; it is expected that a network administrator will statically configure name servers and clients using some out-of-band mechanism.\n\nThis document obsoletes RFCs 2845 and 4635.",
  "draft": "draft-ietf-dnsop-rfc2845bis-09",
  "doi": "10.17487/RFC8945",
  "errata_url": "https://www.rfc-editor.org/errata/rfc8945",
  "obsoletes": [
    "RFC2845",
    "RFC4635"
  ],
  "is_also": [
    "STD93"
  ],
  "urls": {
    "html": "https://rfc.dk/rfc8945/",
    "text": "https://rfc.dk/rfc8945.txt",
    "rfc_editor": "https://www.rfc-editor.org/rfc/rfc8945",
    "datatracker": "https://datatracker.ietf.org/doc/rfc8945/"
  },
  "text_modified": "2020-11-30T23:15:25.757091949Z"
}
