<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.7 (Ruby 3.1.2) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC2181 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2181.xml">
]>


<rfc ipr="trust200902" docName="draft-toorop-dnsop-ranking-dns-data-00" category="std" consensus="true" submissionType="IETF" updates="2181" tocInclude="true" sortRefs="true" symRefs="true">
  <front>
    <title abbrev="Ranking DNS data">Ranking Domain Name System data</title>

    <author initials="P." surname="Hoffman" fullname="Paul Hoffman">
      <organization>ICANN</organization>
      <address>
        <email>paul.hoffman@icann.org</email>
      </address>
    </author>
    <author initials="S." surname="Huque" fullname="Shumon Huque">
      <organization>Salesforce</organization>
      <address>
        <email>shuque@gmail.com</email>
      </address>
    </author>
    <author initials="W." surname="Toorop" fullname="Willem Toorop">
      <organization>NLnet Labs</organization>
      <address>
        <postal>
          <street>Science Park 400</street>
          <city>Amsterdam</city>
          <code>1098 XH</code>
          <country>Netherlands</country>
        </postal>
        <email>willem@nlnetlabs.nl</email>
      </address>
    </author>

    <date year="2024" month="March" day="04"/>

    <area>Operations and Management Area</area>
    <workgroup>Domain Name System Operations</workgroup>
    <keyword>Internet-Draft</keyword> <keyword>DNS</keyword> <keyword>Resolver</keyword> <keyword>Delegation</keyword> <keyword>Revalidation</keyword> <keyword>Authoritative</keyword> <keyword>Name Server Record</keyword> <keyword>NS</keyword> <keyword>Parent</keyword> <keyword>Child</keyword> <keyword>Resource Record Set</keyword>

    <abstract>


<?line 56?>

<t>This document extends the list ranking the trustworthiness of domain name system (DNS) data (see <xref section="5.4.1" sectionFormat="of" target="RFC2181"/>). 
The list is extended with entries for root server names and addresses built-in resolvers, and provided via a root hints file with the lowest trustworthiness, as wel as an entry for data which is verifiable DNSSEC secure with the highest trustworthiness.
This document furthermore assigns ranked values to the positions of the list for easier reference and comparison of trustworthiness of DNS data.</t>



    </abstract>

    <note title="About This Document" removeInRFC="true">
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-toorop-dnsop-ranking-dns-data/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        DNSOP Working Group mailing list (<eref target="mailto:dnsop@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/dnsop/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/dnsop/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/NLnetLabs/draft-toorop-dnsop-ranking-dns-data"/>.</t>
    </note>


  </front>

  <middle>


<?line 62?>

<section anchor="intro"><name>Introduction</name>
<t>This draft's intention is currently just to start re-evaluation and re-thinking of <xref section="5.4.1" sectionFormat="comma" target="RFC2181"/> about ranking trustworthiness of DNS data.</t>

</section>
<section anchor="trustworthiness"><name>Trustworthiness values</name>

<texttable>
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Data</ttcol>
      <c>AAA</c>
      <c>Data from a primary zone file other than occluded data, and all data that is verifiable DNSSEC secure regardless off were it came from</c>
      <c>AA</c>
      <c>Data from a zone transfer other than occluded data</c>
      <c>A</c>
      <c>The authoritative data included in the answer section of an authoritative reply</c>
      <c>A-</c>
      <c>Data from the authority section of an authoritative answer</c>
      <c>BBB</c>
      <c>Occluded data from a primary zone, or occluded data from a zone transfer</c>
      <c>BB</c>
      <c>Data from the answer section of a non-authoritative answer, and non-authoritative data from the answer section of authoritative answers</c>
      <c>B</c>
      <c>Additional information from an authoritative answer, Data from the authority section of a non-authoritative answer, Additional information from non-authoritative answers.</c>
      <c>CCC</c>
      <c>Names and addresses for the root servers from a hints file</c>
      <c>CC</c>
      <c>Names and addresses for the root servers built into resolver software</c>
</texttable>

</section>
<section anchor="iana"><name>IANA Considerations</name>
<t>This document does not require any IANA actions.</t>

</section>
<section anchor="security"><name>Security Considerations</name>
<t>The process of replacing RRsets in a resolvers cache with the RRsets with a higher trustworthiness ranking, either passively or pro-actively by explicit querying, is crucial to the security of the DNS.</t>

</section>


  </middle>

  <back>


    <references title='Normative References' anchor="sec-normative-references">

&RFC2181;


    </references>



<?line 91?>

<section anchor="acknowledgements"><name>Acknowledgements</name>
<t>Thanks to all the people that contributed to the discussion surrounding the re-evaluation of how the trustworthiness of DNS data should be ranked.</t>

</section>


  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA5VXbW/bNhD+zl9xQD+sBSLPyTKgNVAgrtuiBTY3iIN1wLAP
tERbXCRSJSl7bpL/vudIOZVfkrUCWkvk8e65u+fumCzLRNChUiO6kuZGmyW9
tbXUhqayVjTb+KBqKmSQQs7nTq16ctNZ2ihsbiA8osLJRciCtc42WWE8/ndJ
mL8yFs6GQ9E2eFN+RGenL08Fv+N1eHaeDX/JhudC6MaNKLjWh7Ph8NXwTPh2
XmvvtTVh00D447vr90I6JUf0qVFOBux4kqag36WRS1UrE2iMfbFejo758+2U
uFmPBFFGH01QzqiQvWUn4hIcjL9XyttqpVxaVJVaxrPd3kpWuvi2MG5DaZ0O
WFmpuJIMKwcNEM+tK9JyUn4JP0yyNyl1VTxYbF2uOnmcDiKXYUQ+FGKlTKsY
9NLZthkxzE+X+ISXFXLAYb/QKiwG1i1ZSoeynY9o+hu8+03O/c/fkSYhGj2i
v4LNT8hbF5xaeLxtan75WwgZvYyRwz8ibZDOywF9sItFLU1cS5y4lG21swxU
0uivMWJI5WQ8ncZ1lfA3kB+USf5C59KYzo+eoRkMtV9a1TMzK9vamt7yrpmZ
rJRfWIS0b8uXLH6x5K9BbutdK58HdB1j1DPzWVcV+NNb37UTg0wc5bjpETiF
tM1yrQzSiWTf0DlKgDdzHTYjGtdgpCtkndZsASunw1cv6c8P3UprgoPgVIVS
uQos930f1hHRhalguILdgamEMNbVkYCjKHr1fsKlNhIiyzKCUHAyD0Jcl9oT
qreNBaP+DQrKCWao0j5QR4q4EMtxDSaU2ijvyS5wMNYVBwbMiHX1HFx8EZsC
PfdK0e3tTOUcGfp1cD445VMdlvv7FwMCgM4UcCTzqoBHoSQAclp5Qs7IWRvI
pwJia6nUZVE4IMHXvNVVyADFdYUKqrJE4+xKs8aVliSTGsAP0KorlexEZ+1a
AcOei9Dhaa0q/pEmAtpEONG9danzkmHDnF5oOYdCOD97NwHSvHU99aVelkf0
D/bCv2gdJ7i2OCvR7JZoaZwBxi+rFn4GG/U11uvU8RDOh2QxMiW9RoxQo8pF
vnEUwOtGOu2RBJY/zOO2jw8SPWpdFJUSAg3R2aJN6Tt4bp9p3r8Xr3tP5xG3
l588iggJjaexiJBwn6s29E/LsbCoDenAMZVxB21j/US8WGFwkXlAd3vbMeaE
drh0fw8i27bH0ic9u97b7UL64M3e6V2/eh6KO/qDj9IdvWUe/OBzJ+6y9Gx/
f+zBeRqPx6wp2V84W4PbjdO1BD+/WqMSuy2TCfQAdW2eVy3XAccilYasqsRj
CIQnaeww7RwIESO6QEFgTQfKueqj8QSJDiBFKGg0xoONj8JJx1NsiNuB7M/P
JKJNdwAlznyHSsBggJEOSDS07p5zqgHVou5sH1roWdk8qaUzxGrevHkT1Xza
AX8k+ieYCHsuHg1IUnoU26F7ZKzJjmFL2TzcLf5P4xFdPmHqcjEuithlZIWw
L9I8wdnky/FAnXxXkJ/w5Smbj53ygwh7Mpkk3NMjA4J7IwPqDRK/zUpvICQ9
P6Ylzh5udfZh+uDCtAhrXOugUHwcT8c0QbPGINpeVHe6KC6sR5vN3nQoLBAY
yw3zS6t5RJgNReUyhhbjRMy4YjncR+3dPvPd/mPN7XWcx5iaedc/uYpkzs31
6sqrwC2d5+h2yqIJ5GVv0HVC8VumsecO2nLXrk9I6dgSGp51K4VqRXhhO2N/
4vd8gztBU2nckwjXNLeJx3iWuDbX4Eg3D7dubcch+lc3yuYyvxFinN8Yu65U
kf4w6Mc/hkXu7R+GB3EB6jiAuXHGIaxsA8rE9plbvqzM24CC7zAV2udt/IuF
PCYf7nDF9ia1O/GAubTrx65Y2wGGm6ptq4LmqrsSwMH/AI/yfM66DQAA

-->

</rfc>

