DNS ¦w ¥þ ¸ê ·½ ºô ¯¸
Whois¬d¸ß:
RFCs
¦w¥þ¤å¥ó
¤u§@¸s²Õ

DNS ¬ÛÃöªº RFCs ¦Cªí

RFC 4470 Minimally Covering NSEC Records and DNSSEC On-line Signing
S. Weiler SPARTA, Inc. J. Ihren Autonomica AB April 2006

ºK­n

¥»¤å¥ó«ü¥X¦p¦ó«ØºcDNSSEC NSEC resource records¡A­ì¨Óªº¤@¤p³¡¥÷¥]§t¦bRFC 4034¡A ÂǥѲ£¥Í©M¼Ð°O³o¨Ç°O¿ý¡AÅv«Â¦WºÙ¥D¾÷¥i¥H¦³®Äªº¦b¬Y¤@­ÓZone¤¤ÁôÂÃ¥ÑNSEC°O¿ýªº¬ÛÃö°T®§¡C

RFC 3090 DNS Security Extension Clarification on Zone Status
E. Lewis, NAI Labs, March 2001

ºK­n

¥»¤å¥ó´£¥X¤F¦w¥þºô°ìªº©w¸q¡B»¡©ú¡A¥H¤Î§ó·s¤F RFC 2535 ªº³¡¥÷¤å¥ó¡C RFC 2535 ©w¸q¡G¤@­Óºô°ì¬O§_¦w¥þ¬O®Ú¾Úºtºâªk¦Ó©wªº¡A¥ç§Y¤@­Óºô°ì¨Ï¥Î RSA keys ¬O¦w¥þªº¡A ¦Ó¨Ï¥Î DSA keys «h§_¡C³o¥÷¤å¥ó§ïÅܤF³o­Ó©w¸q¡A¤@­Óºô°ì¬O§_¦w¥þ¸ò¥L¥Î ¤£¥Îºtºâªk©Î¥Î­þ¤@ºØºtºâªkµLÃö¡C¬°¤F§ó¥[²¤Æ¹ïºô°ìª¬ºAªº­­¨î¡A¥»¤å¥ó¤Ï¹ï "¹êÅç©Ê¦w¥þ" ª¬ºA¡C

RFC 3008 DNS Security (DNSSEC) ñ³¹±ÂÅv
B. Wellington, Nominum, November 2000

ºK­n

³o¥÷¤å¥ó´£¥X¤@­Ó DNSSEC ñ³¹±ÂÅvªº­×­q¼Ò²Õ¡C³o­Ó­×­q¼Ò²Õ§â¸û¦­ªº¤å¥ó °µ¤F²M·¡ªº»¡©ú¡A¨Ã¥B¼W¥[¤FÃB¥~ªº­­¨î¥H²¤Æ¦w¥þ¸ÑªRµ{§Ç¡C ³o¤]·|¼vÅT¨ì¥Î¨Óñ¸p°O¿ý¶°¦Xªº±KÆ_ªº±ÂÅv¡C

RFC 3007 DNS ¦w¥þ°ÊºA§ó·s
B. Wellington, Nominum, November 2000

ºK­n

¥»¤å¥ó´£¥X¤@­ÓÅý DNS ¦w¥þ¦a°õ¦æ°ÊºA§ó·sªº¤èªk¡C¦¹¤èªk·N¹Ï¹F¨ìÆF¬¡©Ê¤Î¥i¥Î©Ê¡A ¦P®É¤]ºÉ¥i¯à¦a¤£§ó§ï¨ì¥Ø«eªº¨ó©w¡C¦b¦¹¡A°ÊºA§ó·sªº°T®§»{ÃÒ±q¸ê®Æªº DNSSEC ½T»{µ{§Ç¤¤¤ÀÂ÷¥X¨Ó¡C ³q°T¦w¥þ¬O°ò©ó½Ð¨Dªº»{ÃÒ¡A¨Ã¥B³z¹L¥æ©ö¨Ó´£¨Ñ±ÂÅv¡C

RFC 2931 DNS ½Ð¨D¤Î¥æ©öñ³¹ (SIG(0)s)
D. Eastlake, Motorola, September 2000

ºK­n


RFC 2535 ¤¤´£¨ì¤F DNS ªº©µ¦ù¥\¯à¡A¥¦¯à°÷³z¹L¨Ï¥Î¥[±K¼Æ¦ìñ³¹¡A ´£¨Ñ¨Ó·½¸ê®Æªº§¹¾ã©Ê¤Î¥æ©ö»{ÃÒµ¹¨ã¦³¦w¥þª¾Ä±ªº¸Ñ;¹¤ÎÀ³¥Îµ{¦¡¡C ¹ê§@ªº¸gÅç«ü¥X¡A½Ð¨D¤Î¥æ©öñ³¹¸ê·½°O¿ý (SIG(0)s) »Ý­n°µ¨Ç­×§ï¡A³o¨Ç­×§ï¤]¦C¦b¥»¤å¥óùØ­±¡C

RFC 2930 DNS ±KÆ_«Ø¥ß (TKEY RR)
D. Eastlake, Motorola, September 2000

ºK­n

RFC 2845 ´£¨Ñ¤@­Ó³z¹L¥æ©öñ³¹ (TSIG) ¸ê·½°O¿ý¡A ¨Ï¥Î¦@¨É±KÆ_¨Ó»{ÃÒ DNS ½Ð¨D¤Î¦^À³ªº¤èªk¡CµM¦Ó¡A°£¤F¤â°Ê¥æ´«±KÆ_¤§¥~¡A¥¦¨Ã¨S¦³´£¨Ñ«Ø¥ß±KÆ_ªº¾÷¨î¡C ¥»¤å¥ó´£¨Ñ¤F¤@­Ó¤èªk¡A¦b¤@¨Ç¤£¦Pªº¼Ò¦¡¤U¡A §Q¥Î¥æ©ö±KÆ_ (TKEY) ¸ê·½°O¿ý¦b DNS ¸Ñ;¹»P¦øªA¾¹¤§¶¡«Ø¥ß¦@¨É±KÆ_¡C

RFC 2845 DNS ±KÆ_¥æ©ö»{ÃÒ (TSIG)
P. Vixie, O. Gudmundsson, D. Eastlake, B. Wellington. May 2000

ºK­n

¦¹¨ó©w¤¹³\¥æ©ö¼h¯Åªº»{ÃҨϥΦ@¨É±KÆ_ (shared secrets) ¤Î³æ¦VÂø´ê¨ç¼Æ (one way hasging)¡C ¥¦¯à°÷¥Î¨Ó»{ÃÒ±q³Q»{¥iªº«È¤áºÝ¨Óªº°ÊºA§ó·s¡A©Î¬O¥Î¨Ó»{ÃÒ±q³Q»{¥i¹Lªº»¼¦^¦WºÙ¦øªA¾¹¨Óªº¦^À³°T®§¡C ¦b¤À°t¦@¨É±KÆ_®É¨Ã¨S¦³°µ¥ô¦óªº¹w³Æ¡A¦Ó¬O´Á«Ýºô¸ôºÞ²zªÌ¯à°÷ÀRºA¦a³]©w¦WºÙ¦øªA¾¹¤Î«È¤áºÝ¡C ¤£­n¥Î¨ìºô¸ô¾÷¨î¡A¨Ò¦p¥ÎºÏ¤ù¶l±Hµ¥¤èªk¡Aª½¨ì key ¤À°tªº¦w¥þ¦Û°Ê¾÷¨î¯à°÷¨Ï¥Î¬°¤î¡C

RFC 2541 DNS ¦w¥þ¾Þ§@¦Ò¶q
D. Eastlake, IBM, March 1999

ºK­n

DNS ¦w¥þ©Ê¬O¥H±K½X§Þ³N¬°°ò¦ªº¡C³o¨Ç±K½X§Þ³Nªº¦w¥þ±j«×©Ò¤£¥i©Î¯Êªº¬O¡A¤p¤ß¤Îª`·N±KÆ_ (key) ¤Îñ³¹ (signature) ªº²£¥Í¡B¦³®Ä®É¶¡¡B¤j¤p¤ÎÀx¦sµ¥¾Þ§@¤è­±¡C °£¦¹¤§¥~¡AÁÙ¥²¶·¯S§O¯d·N¤W¼hºô°ìªº¦w¥þ©Ê¡A¯S§O¬O root ºô°ì¡C³o¥÷¤å¥ó¥Î¤F KEY ¤Î SIG DNS ¸ê·½°O¿ý (RR) ¨Ó°Q½×¥Î¨Ó³s½uªº±KÆ_¤Îñ³¹ªº¾Þ§@³¡¥÷¡C

RFC 2537 DNS ùتº RSA/MD5 KEYs ¤Î SIGs
D. Eastlake, IBM, March 1999

ºK­n

³o¥÷¤å¥ó´£¨ì¦b DNS ùØÀx¦sñ³¹ªº¼Ð·Ç¤èªk¡A¦¹Ã±³¹¬O¥H RSA key ¤Î RSA/MD5 ¬°°ò¦¡C ¦b¦¹·|§Q¥Î¨ì DNS KEY ¤Î SIG ¸ê·½°O¿ý¡C

RFC 2536 DNS ùتº DSA KEYs ¤Î SIGs
D. Eastlake, IBM, March 1999

ºK­n

³o¥÷¤å¥ó´£¨ì¦b DNS ùØÀx¦s¬ü°ê¬F©²¼Æ¦ìñ³¹ºtºâªkªº±KÆ_¤Îñ³¹ªº¼Ð·Ç¤èªk¡C ¦b¦¹·|§Q¥Î¨ì DNS KEY ¤Î SIG ¸ê·½°O¿ý¡C

RFC 2535 DNS ¦w¥þ©µ¦ù
D. Eastlake, IBM, March 1999

ºK­n

RFC 2535 ¤¤´£¨ì¤F DNS ªº©µ¦ù¥\¯à¡A¥¦¯à°÷³z¹L¨Ï¥Î¥[±K¼Æ¦ìñ³¹¡A ´£¨Ñ¨Ó·½¸ê®Æªº§¹¾ã©Ê¤Î¥æ©ö»{ÃÒµ¹¨ã¦³¦w¥þª¾Ä±ªº¸Ñ;¹¤ÎÀ³¥Îµ{¦¡¡C ³o¨Ç¼Æ¦ìñ³¹¥]¨ç¦b¦w¥þºô°ìªº¸ê·½°O¿ýùØ¡C¦¹¥~¡A¦b¬Y¨Ç±¡ªp¤§¡A ³o¼Ëªº¦w¥þ©Ê¤]¯à°÷´£¨Ñ«D¦w¥þª¾Ä±ªº DNS ¦øªA¾¹¡C
¦¹©µ¦ù¥\¯à´£¨Ñ¤F¦b DNS ùØÀx¦s±ÂÅvªº¤½¶}©úÆ_¡CKey ªºÀx¦s¯à¹³ DNS ¦w¥þ¤@¼Ë¡A¤ä´©¤@¯ë¤½¶}©úÆ_ªº¤À°tªA°È¡C ³o¨ÇÀx¦s°_¨Óªº Key Åý¨ã¦w¥þª¾Ä±ªº¸Ñ;¹¯à°÷¾Ç²ß»{ÃÒºô°ìªº Key¡A°£¤F­è³Q³]©wªº Key ¤§¥~¡C »P DNS ¦WºÙ¬Û³sôªº Key ¯à°÷³Q­«·s¨ú±o¥H¤ä´©¨ä¥¦ªº¨ó©w¡C
°£¦¹¤§¥~¡A¦¹¦w¥þ©µ¦ù¥\¯à¤]´£¨Ñ¤F DNS ¨ó©w¥æ©ö¤Î½Ð¨Dªº¿ï¾Ü©Ê»{ÃÒ¡C³o¥÷¤å¥ó¤]±N RFC 2065 ùØ¡A¦­´Á¤@¨Ç¼¶¼gªÌ¤Î¨Ï¥ÎªÌªº¦^À³¦X¨Ö¶i¨Ó¡C

RFC 1713 DNS °»¿ù¤u¨ã
A. Romao, FCCN, November 1994

ºK­n

¾¨ºÞ DNS ¤w³Q¼sªxªº¨Ï¥Î (¤j³¡¥÷®É¶¡¨S¦³¤Þ°_¤H­Ìªºª`·N)¡A¦ý¬O¤H­Ì«o©¹©¹©¿²¤¤F¥¦ªº¦s¦b¡C ¤H­Ì»{¬°¡A¯S§O¬O¨t²ÎºÞ²zªÌ»{¬°¡A¥u­n¨º¨Ç»Ý­n¦WºÙ¹ï¬M¦ì§}ªºÀ³¥Î³nÅé¯à°÷«ùÄò¦a¹B§@´N¥i¥H¤F¡A ¦Ó©¿µ¸¤F¥i¯àµo¥Íªº²§±`²{¶H¡C³o¥÷¤å¥ó´£¨Ñ¤F¤@¨Ç¦³¥Îªº¤u¨ã¡AÅýºô°ìºÞ²zªÌ¯à°÷°»´ú¤Î­×¥¿³o¨Ç²§±`²{¶H¡C

RFC 1536 Common DNS Implementation Errors and Suggested Fixes
A. Kumar, J. Postel, C. Neuman, P. Danzig, S. Miller, October 1993

ºK­n

¹L¥h´X¦~¨Ó¡A±q NSFnet °©·F¤W¥i¥H¬Ý¥X DNS ¬y¶q¤w¸gÃz¬µ¶}¨Ó¡C¤£¦Pªº DNS ³nÅé¡A¥H¤Î³o¨Ç³nÅ餤¤£¦Pªºª©¥»¡A ¥¦­Ì©¼¦¹¤§¶¡ªº¤¬°Ê¡A²£¥Í¤F¤j¶q¤£¥²­nªº¬y¶q¡CInternet ¤Wªº¬ã¨s¤H­û¤w¸g¶}©l¹Á¸ÕµÛ§â³o¨Ç¤¬°Ê¤å¥ó¤Æ¡A ¨Ã°O¿ý¤U³o¨Ç¬y¶qªº¯S¼x¡A¥B³]­p¤F¨¾ªv³o¨Ç³nÅé®zÂIªºµ{¦¡¡C
³o¥÷¤å¥ó°O¿ý¤F¤wª¾ªº DNS °ÝÃD¡A¤Î¨ä­×¥¿¸ê°T¡C¥HÅý¤H­Ìª¾¹D­þ¨Ç°ÝÃD¥²¶·¤p¤ß¡A¥H¤Î¦p¦ó­×½Æ¤w¾D·l·´ªº³¡¥÷¡C

RFC 1535 A Security Problem and Proposed Correction With Widely Deployed DNS Software
E. Gavron., ACES Research Inc., October 1993

ºK­n

³o¥÷¤å¥ó°Q½×¨ì¥Ø«e¤@¨Ç¦WºÙ¸ÑĶ«È¤áºÝ¦³­Óº|¬}¡A³o­Óº|¬}¼ÉÅS¤F³o¨Ç¸Ñ;¹¦b¬d¸ß¤Wªº¦w¥þ®zÂI¡C ·í¨Ï¥ÎªÌ´£¨Ñ¤F³¡¥÷ªººô°ì¦WºÙ®É¡A«Ü®e©ö³Q®zÂI§ðÀ»¡C³o¥÷¤å¥ó¥Î¤F¤@­Ó¦X¾Aªº¨Ò¤l«ü¥X¤F³o­Óº|¬}¡A ¨Ã¥B´£¥X¤F¸Ñ¨M¤èªk¡C

 


Copyright 2002 °]¹Îªk¤H¥xÆWºô¸ô¸ê°T¤¤¤ß All Rights Reserved.
100»O¥_¥«Ã¹´µºÖ¸ô¤G¬q9¸¹4¼Ó¤§2
4F-2, No. 9, Roosevelt Rd., Sec. 2, Taipei 100, Taiwan, R.O.C.
TEL¡G886-2-23411313¡EFAX¡G886-2-2396-8832
E-mail¡Gservice@twnic.net.tw


¤¤¤ß¦a¹Ï