I-D Action: draft-ranjbar-dane-anchored-identity-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178461748166.196860.2715461109762225405@dt-datatracker-d4d6ff9d9-fsx7d> |
Internet-Draft draft-ranjbar-dane-anchored-identity-00.txt is now available. Title: DANE-Anchored Identity for Network Clients, Devices, and Autonomous Agents Author: Kaveh Ranjbar Name: draft-ranjbar-dane-anchored-identity-00.txt Pages: 12 Dates: 2026-07-21 Abstract: A rapidly growing set of protocols for autonomous agents, connected devices, and machine workloads bootstraps trust in an endpoint's public key over the Web PKI together with an HTTPS .well-known fetch, a bespoke certificate authority, or a centralized registry. These approaches inherit domain-takeover exposure, depend on a reachable call-home endpoint, are not verifiable across organizational boundaries, and frequently provide no timely revocation. This document describes a complementary identity model in which an endpoint's key is anchored directly in DNSSEC-signed DNS using DANE (a TLSA record), bound to a routable address whose reverse and forward names are served from a signed zone, and described by RDAP. The model, consistent with the architecture developed in the DANE Authentication for Network Clients Everywhere (DANCE) working group, lets any relying party verify an endpoint's identity from stock DNS tooling with no account or private trust root, and lets the identity's holder revoke it worldwide at DNS TTL. It is intended as an anchor that existing agent-, device-, and content-identity schemes can adopt without abandoning their own transports or object formats. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ranjbar-dane-anchored-identity/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ranjbar-dane-anchored-identity-00 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]