<?xml version="1.0" encoding="US-ASCII"?>
<?xml-stylesheet type='text/xsl' href='rfc2629.xslt' ?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd" [
<!ENTITY rfc1034 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.1034.xml">
<!ENTITY rfc1035 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.1035.xml">
<!ENTITY rfc2119 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY rfc2986 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2986.xml">
<!ENTITY rfc3339 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3339.xml">
<!ENTITY rfc4033 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.4033.xml">
<!ENTITY rfc4034 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.4034.xml">
<!ENTITY rfc4035 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.4035.xml">
<!ENTITY rfc4509 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.4509.xml">
<!ENTITY rfc4880 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.4880.xml">
<!ENTITY rfc5280 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5280.xml">
<!ENTITY rfc5011 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5011.xml">
<!ENTITY rfc5155 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5155.xml">
<!ENTITY rfc5652 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5652.xml">
<!ENTITY rfc5702 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5702.xml">
<!ENTITY rfc6781 PUBLIC "" "http://xml.resource.org/public/rfc/bibxml/reference.RFC.6781.xml">
]>

<?rfc strict="yes" ?>
<?rfc toc="yes"?>
<?rfc symrefs="yes"?>
<?rfc sortrefs="yes"?>
<?rfc compact="yes"?>
<?rfc subcompact="no"?>

<rfc number="7958" 
     category="info"
     submissionType="independent"
     consensus="yes"
     ipr="trust200902">

  <front>
    <title abbrev="Root Zone Trust Anchor Publication">DNSSEC Trust
      Anchor Publication for the Root Zone</title>

    <author initials='J.' surname="Abley" fullname='Joe Abley'>
      <organization>Dyn, Inc.</organization>
      <address>
        <postal>
          <street>300-184 York Street</street>
          <city>London</city>
          <region>ON</region>
          <code>N6A 1B5</code>
          <country>Canada</country>
        </postal>
        <phone>+1 519 670 9327</phone>
        <email>jabley@dyn.com</email>
      </address>
    </author>

    <author fullname="Jakob Schlyter" initials="J." surname="Schlyter">
      <organization>Kirei AB</organization>
      <address>
        <email>jakob@kirei.se</email>
      </address>
    </author>

    <author fullname="Guillaume Bailey" initials="G." surname="Bailey">
      <organization>Independent</organization>
      <address>
        <email>GuillaumeBailey@outlook.com</email>
      </address>
    </author>

    <author fullname="Paul Hoffman" initials="P." surname="Hoffman">
      <organization>ICANN</organization>
      <address>
        <email>paul.hoffman@icann.org</email>
      </address>
    </author>

    <date month="August" year="2016"/>

    <abstract>
      <t>The root zone of the Domain Name System (DNS) has been
        cryptographically signed using DNS Security Extensions
        (DNSSEC).</t>

      <t>In order to obtain secure answers from the root zone of the
        DNS using DNSSEC, a client must configure a suitable trust
        anchor.  This document describes the format and publication
        mechanisms IANA has used to distribute the DNSSEC trust anchors.</t>

    </abstract>
  </front>

  <middle>
    <section title="Introduction">
      <t>The Domain Name System (DNS) is described in <xref
    target="RFC1034" /> and <xref target="RFC1035" />. DNS Security
    Extensions (DNSSEC) are described in <xref
    target="RFC4033" />, <xref target="RFC4034" />, <xref
    target="RFC4035" />, <xref target="RFC4509" />, <xref
    target="RFC5155" />, and <xref target="RFC5702" />.</t>

      <t>A discussion of operational practices relating to DNSSEC can be found
      in <xref target="RFC6781" />.</t>

      <t>In the DNSSEC protocol, Resource Record Sets (RRSets) are signed
      cryptographically. This means that a response to a query contains
      signatures that allow the integrity and authenticity of the RRSet to be
      verified. DNSSEC signatures are validated by following a chain of signatures to
      a "trust anchor". The reason for trusting a trust anchor is
      outside the DNSSEC protocol, but having one or more trust anchors is
      required for the DNSSEC protocol to work.</t>

      <t>The publication of trust anchors for the root zone of the DNS is an
      IANA function performed by ICANN. A detailed description of corresponding
      key management practices can be found in <xref target="DPS"/>, which can
      be retrieved from the IANA Repository at &lt;https://www.iana.org/dnssec/&gt;.</t>

      <t>This document describes the formats and distribution methods of DNSSEC trust anchors
      that have been used by IANA for the root zone of the DNS since 2010. Other organizations might have
      different formats and mechansims for distributing DNSSEC trust anchors
      for the root zone; however, most operators and software vendors have
      chosen to rely on the IANA trust anchors.</t>

      <t>It is important to note that at the time of this writing, IANA
      intends to change the formats and distribution methods in the future.
      If such a change happens, IANA will publish the changes on its web site
      at &lt;https://www.iana.org/dnssec/files&gt;.</t>

      <t>The formats and distribution methods described in this document are
      a complement to, not a substitute for, the
      automated DNSSEC trust anchor update protocol described in <xref target="RFC5011" />.
      That protocol allows for secure in-band succession of trust anchors 
      when trust has already been established. 
      This document describes one way to establish an initial trust anchor that
      can be used by <xref target="RFC5011" />.</t>

<section title="Definitions">

<t>The term "trust anchor" is used in many different contexts in the security
community. Many of the common definitions conflict because they are specific to
a specific system, such as just for DNSSEC or just for S/MIME messages.</t>

<t>In cryptographic systems with hierarchical structure, a trust anchor is an
authoritative entity for which trust is assumed and not derived. The format of
the entity differs in different systems, but the basic idea, that trust is
assumed and not derived, is common to all the common uses of the term "trust
anchor".</t>

<t>The root zone trust anchor formats published by IANA are defined in <xref
target="ta_formats"/>. <xref target="RFC4033"/> defines a trust anchor as "A
configured DNSKEY RR or DS RR hash of a DNSKEY RR". Note that the formats
defined here do not match the definition of "trust anchor" from <xref
target="RFC4033"/>; however, a system that wants to convert the trusted material
from IANA into a Delegation Signer (DS) RR can do so.</t>

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD",
"SHOULD NOT", "RECOMMENDED",  "MAY", and "OPTIONAL" in this document are to be
interpreted as described in <xref target='RFC2119'/>.</t>

</section>
      
    </section>

    <section title="IANA DNSSEC Root Zone Trust Anchor Formats and Semantics" anchor="ta_formats">

      <t>IANA publishes trust anchors for the root zone in three formats:

         <list style="symbols">

           <t>an XML document that contains the hashes of the DNSKEY records</t>

           <t>certificates in PKIX format <xref target="RFC5280"/>
           that contain DS records and the full public key
           of DNSKEY records</t>

           <t>Certificate Signing Requests (CSRs) in PKCS #10 format <xref
           target="RFC2986"/> that contain DS records and the full public key
           of DNSKEY records</t>

         </list>

       These formats and the semantics associated with each are described in
       the rest of this section.
       </t>

      <section title="Hashes in XML" anchor="hashes_in_xml">

        <t>The XML document contains a set of hashes for the DNSKEY records
          that can be used to validate the root zone. The hashes are
          consistent with the defined presentation format of DS
          resource records from <xref target="RFC4034"/>.</t>

        <section title="XML Syntax" anchor="xml_syntax">


          <t>A RELAX NG Compact Schema <xref target="RELAX-NG"/> for the documents used to publish
            trust anchors is given in <xref target="schemafig"/>.</t>

          <figure anchor="schemafig"><artwork><![CDATA[
datatypes xsd = "http://www.w3.org/2001/XMLSchema-datatypes"

start = element TrustAnchor {
    attribute id { xsd:string },
    attribute source { xsd:string },
    element Zone { xsd:string },

    keydigest+
}

keydigest = element KeyDigest {
    attribute id { xsd:string },
    attribute validFrom { xsd:dateTime },
    attribute validUntil { xsd:dateTime }?,

    element KeyTag {
            xsd:nonNegativeInteger { maxInclusive = "65535" } },
    element Algorithm {
            xsd:nonNegativeInteger { maxInclusive = "255" } },
    element DigestType {
            xsd:nonNegativeInteger { maxInclusive = "255" } },
    element Digest { xsd:hexBinary }
}]]></artwork></figure>

        </section>

        <section title="XML Semantics" anchor="xml_semantics">

<t>The TrustAnchor element is the container for all of the trust anchors in the
file.</t>

<t>The id attribute in the TrustAnchor element is an opaque string that identifies
the set of trust anchors. Its value has no particular semantics.
Note that the id element in the TrustAnchor element is different than the id
element in the KeyDigest element, described below.</t>

<t>The source attribute in the TrustAnchor element gives information about where
to obtain the TrustAnchor container. It is likely to be a URL and is advisory only.</t>

<t>The Zone element in the TrustAnchor element states to which DNS zone this container
applies. The root zone is indicated by a single period (.) character without any
quotation marks.</t>

<t>The TrustAnchor element contains one or more KeyDigest elements. Each KeyDigest
element represents the digest of a DNSKEY record in the zone defined in the
Zone element.</t>

<t>The id attribute in the KeyDigest element is an opaque string that identifies
the hash. Its value is used in the file names and URI of the other trust anchor
formats. This is described in <xref target="https_and_http"/>.
For example, if the value of the id attribute in the KeyDigest element
is "Kjqmt7v", the URI for the CSR that is associated with this hash will be
&lt;https://data.iana.org/root-anchors/Kjqmt7v.csr&gt;.
Note that the id element in the KeyDigest element is different than the id
element in the TrustAnchor element described above.</t>

<t>The validFrom and validUntil attributes in the KeyDigest element specify
the range of times that the KeyDigest element can be used as a trust anchor.
Note that the KeyDigest element is optional; if it is not given, the
trust anchor can be used until a KeyDigest element covering the same
DNSKEY record, but having a validUntil attribute, is trusted by the relying party.
Relying parties SHOULD NOT use a KeyDigest outside of the time range given
in the validFrom and validUntil attributes.</t>

<t>The KeyTag element in the KeyDigest element contains the key tag for the
DNSKEY record represented in this KeyDigest.</t> 

<t>The Algorithm element in the KeyDigest element contains the signing algorithm
identifier for the DNSKEY record represented in this KeyDigest.</t> 

<t>The DigestType element in the KeyDigest element contains the digest algorithm
identifier for the DNSKEY record represented in this KeyDigest.</t> 

<t>The Digest element in the KeyDigest element contains the hexadecimal
representation of the hash for the DNSKEY record represented in this KeyDigest.</t>

        </section>

        <section title="Converting from XML to DS Records" anchor="xml_to_ds">

<t>The display format for the DS record that is the equivalent of a KeyDigest element can be constructed
by marshaling the KeyTag, Algorithm, DigestType, and Digest elements. For example, assume that the TrustAnchor
element contains:
<figure><artwork><![CDATA[
<?xml version="1.0" encoding="UTF-8"?>
<TrustAnchor
   id="AD42165F-3B1A-4778-8F42-D34A1D41FD93"
   source="http://data.iana.org/root-anchors/root-anchors.xml">
<Zone>.</Zone>
<KeyDigest id="Kjqmt7v" validFrom="2010-07-15T00:00:00+00:00">
<KeyTag>19036</KeyTag>
<Algorithm>8</Algorithm>
<DigestType>2</DigestType>
<Digest>
49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5
</Digest>
</KeyDigest>
</TrustAnchor>]]></artwork></figure>

The DS record would be:
<figure><artwork><![CDATA[
. IN DS 19036 8 2
   49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5 ]]></artwork></figure></t>

        </section>

        <section title="XML Example" anchor="xml_example">

          <t><xref target="eg1"/> describes two fictitious trust anchors for the
            root zone.</t>

          <figure anchor="eg1"><artwork><![CDATA[
<?xml version="1.0" encoding="UTF-8"?>

<TrustAnchor
    id="AD42165F-B099-4778-8F42-D34A1D41FD93"
    source="http://data.iana.org/root-anchors/root-anchors.xml">
    <Zone>.</Zone>
    <KeyDigest id="42"
               validFrom="2010-07-01T00:00:00-00:00"
               validUntil="2010-08-01T00:00:00-00:00">
        <KeyTag>34291</KeyTag>
        <Algorithm>5</Algorithm>
        <DigestType>1</DigestType>
        <Digest>c8cb3d7fe518835490af8029c23efbce6b6ef3e2</Digest>
    </KeyDigest>
    <KeyDigest id="53"
               validFrom="2010-08-01T00:00:00-00:00">
        <KeyTag>12345</KeyTag>
        <Algorithm>5</Algorithm>
        <DigestType>1</DigestType>
        <Digest>a3cf809dbdbc835716ba22bdc370d2efa50f21c7</Digest>
    </KeyDigest>
</TrustAnchor>]]></artwork></figure>

        </section>
      </section>

      <section title="Certificates" anchor="certs">

         <t>Each public key that can be used as a trust anchor is represented as a
          certificate in PKIX format. Each certificate is signed by the ICANN
          certificate authority. The SubjectPublicKeyInfo in the certificate
          represents the public key of the Key Signing Key (KSK).
          The Subject field has the following attributes:

          <list style="hanging">
            <t hangText="O: ">the string "ICANN".</t>

            <t hangText="OU:">the string "IANA".</t>

            <t hangText="CN:">the string "Root Zone KSK" followed
              by the time and date of key generation in the format
              specified in <xref target="RFC3339"/>.
              For example, a CN might be "Root Zone KSK 2010-06-16T21:19:24+00:00".</t>

            <t hangText="resourceRecord:">a string in
              the presentation format of the DS <xref target="RFC4034"/>
              resource record for the DNSSEC public key.</t>
          </list>
        </t>

        <t>The "resourceRecord" attribute in the Subject is defined as follows:
<figure><artwork><![CDATA[
ResourceRecord
  { iso(1) identified-organization(3) dod(6) internet(1) security(5)
    mechanisms(5) pkix(7) id-mod(0) id-mod-dns-resource-record(70) }

DEFINITIONS IMPLICIT TAGS ::=

BEGIN

-- EXPORTS ALL --

IMPORTS

caseIgnoreMatch FROM SelectedAttributeTypes
    { joint-iso-itu-t ds(5) module(1) selectedAttributeTypes(5) 4 }

;

iana OBJECT IDENTIFIER ::= { iso(1) identified-organization(3)
    dod(6) internet(1) private(4) enterprise(1) 1000 }

iana-dns OBJECT IDENTIFIER ::= { iana 53 }

resourceRecord ATTRIBUTE ::= {
    WITH SYNTAX IA5String
    EQUALITY MATCHING RULE caseIgnoreMatch
    ID iana-dns
}

END]]></artwork></figure>
        </t>
     </section>

      <section title="Certificate Signing Requests" anchor="csrs">

        <t>Each public key that can be used as a trust anchor is represented as a
          CSR in PKCS #10 format. The SubjectPublicKeyInfo
          and Subject field are the same as for certificates
          (see <xref target="certs"/> above).</t>

      </section>
    </section>

    <section anchor="mechanisms" title="Root Zone Trust Anchor Retrieval">
 
     <section title="Retrieving Trust Anchors with HTTPS and HTTP" anchor="https_and_http">

        <t>Trust anchors are available for retrieval using HTTPS and HTTP.
          </t>

        <t>In this section, all URLs are given using the "https:" scheme. If
          HTTPS cannot be used, replace the "https:" scheme with "http:".</t>

        <t>The URL for retrieving the set of hashes described in <xref target="hashes_in_xml"/>
     	   is &lt;https://data.iana.org/root-anchors/root-anchors.xml&gt;.</t>

        <t>The URL for retrieving the PKIX certificate described in <xref target="certs"/> is
          &lt;https://data.iana.org/root-anchors/KEYDIGEST-ID.crt&gt;,
          with the string "KEYDIGEST-ID" replacing the "id" attribute from the KeyDigest element
          from the XML file, as described in <xref target="xml_semantics"/>.</t>

        <t>The URL for retrieving the CSR described in <xref target="csrs"/> is
          &lt;https://data.iana.org/root-anchors/KEYDIGEST-ID.csr&gt;,
          with the string "KEYDIGEST-ID" replacing the "id" attribute from the KeyDigest element
          from the XML file, as described in <xref target="xml_semantics"/>.</t>

      </section>
   </section>

<section title="Accepting DNSSEC Trust Anchors" anchor="trusting_anchors">

<t>A validator operator can choose whether or not to accept the trust anchors
described in this document using whatever policy they want. In order to help
validator operators verify the content and origin of trust anchors they
receive, IANA uses digital signatures that chain to an ICANN-controlled
Certificate Authority (CA) over
the trust anchor data.</t>

<t>It is important to note that the ICANN CA is not a DNSSEC trust anchor.
Instead, it is an optional mechanism for verifying the content and origin of
the XML and certificate trust anchors. It is also important to note that the
ICANN CA cannot be used to verify the origin of the trust anchor in the CSR
format.</t>

<t>The content and origin of the XML file can be verified using
a digital signature on the file. IANA provides a detached Cryptographic
Message Syntax (CMS) <xref
target="RFC5652"/> signature that chains to the ICANN CA with the XML file. The URL for a
detached CMS signature for the XML file is
&lt;https://data.iana.org/&wj;root&nbhy;anchors/&wj;root&nbhy;anchors.p7s&gt;.</t>

<t>(IANA also provided a detached OpenPGP <xref target="RFC4880"/> signature as
a second parallel verification mechanism for the first trust anchor publication
but has indicated that it will not use this parallel mechanism in the future.)</t>

<t>Another method IANA uses to help validator operators verify the content and
origin of trust anchors they receive is to use the Transport Layer Security (TLS) protocol for distributing
the trust anchors. Currently, the CA used for data.iana.org is well known, that
is, one that is a WebTrust-accredited CA. If a system
retrieving the trust anchors trusts the CA that IANA uses for the
"data.iana.org" web server, HTTPS SHOULD be used instead of HTTP in order to
have assurance of data origin.</t>

</section>

    <section title="IANA Considerations">
      <t>This document defines id-mod-dns-resource-record, value 70 (see <xref
      target="certs"/>), in the "SMI Security for PKIX Module Identifier"
      registry.</t>

    </section>

    <section title="Security Considerations">
      <t>This document describes how DNSSEC trust anchors for the
        root zone of the DNS are published.
        Many DNSSEC clients will only configure IANA-issued trust
        anchors for the DNS root to perform validation.
        As a consequence,
        reliable publication of trust anchors is important.</t>

      <t>This document aims to specify carefully the means by which such trust
      anchors are published, with the goal of making it easier for those
      trust anchors to be integrated into user environments.</t>
    </section>

  </middle>

  <back>
    <references title="Normative References">
      &rfc1034;
      &rfc1035;
      &rfc2119;
      &rfc2986;
      &rfc3339;
      &rfc4033;
      &rfc4034;
      &rfc4035;
      &rfc4509;
      &rfc5011;
      &rfc5280;
      &rfc5155;
      &rfc5652;
      &rfc5702;
      &rfc6781;
    </references>

    <references title="Informative References">

      &rfc4880;


      <reference anchor="DPS"
             target="https://www.iana.org/dnssec/icann-dps.txt">
        <front>
          <title abbrev="Root Zone KSK Operator DPS">DNSSEC Practice Statement for the Root Zone KSK Operator</title>
          <author fullname="Fredrik Ljunggren" initials="F." surname="Ljunggren">
	    <organization>Kirei AB</organization>
          </author>
          <author fullname="Tomofumi Okubo" initials="T." surname="Okubo">
      	    <organization>ICANN</organization>
          </author>
          <author fullname="Richard Lamb" initials="R." surname="Lamb">
            	    <organization>ICANN</organization>
          </author>
          <author fullname="Jakob Schlyter" initials="J." surname="Schlyter">
      	    <organization>Kirei AB</organization>
          </author>
          <date month="October" year="2015" />
        </front>
      </reference>

<reference anchor="RELAX-NG" 
	   target="https://www.oasis-open.org/committees/relax-ng/compact-20021121.html">
  <front>
    <title>RELAX NG Compact Syntax</title>
    <author fullname="James Clark" initials="J." surname="Clark">
      <organization></organization>
    </author>
    <date month="November" year="2002"/>
  </front>
    <seriesInfo name="Committee" value="Specification"/>
    </reference>
    </references>

    <section title="Historical Note">
      <t>The first KSK for use in the root zone of the DNS was
    generated at a key ceremony at an ICANN Key Management Facility
    (KMF) in Culpeper, Virginia, USA on 2010-06-16.  This key
    entered production during a second key ceremony held at an
    ICANN KMF in El Segundo, California, USA on 2010-07-12.
    The resulting trust anchor was first published on 2010-07-15.</t>
    </section>

<section anchor="Acknowledgements" title="Acknowledgements" numbered="no">
<t>Many pioneers paved the way for the deployment of DNSSEC in the root
zone of the DNS, and the authors hereby acknowledge their substantial
collective contribution.</t>

<t>This document incorporates suggestions made by Alfred Hoenes and Russ
Housley, whose contributions are appreciated.</t>
</section>

  </back>
</rfc>
