I-D Action: draft-ranjbar-dane-did-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178478984968.526595.7526419531238172650@dt-datatracker-d4d6ff9d9-fsx7d> |
Internet-Draft draft-ranjbar-dane-did-00.txt is now available. Title: Rooting Decentralized Identifiers in DNSSEC: A DANE-EE Key-Binding Profile Author: Kaveh Ranjbar Name: draft-ranjbar-dane-did-00.txt Pages: 15 Dates: 2026-07-22 Abstract: Several Decentralized Identifier (DID) methods root trust in a DNS name: did:web binds an identifier to a domain and today verifies its keys over the Web PKI, did:dns serves DID data from DNS resource records, and did:webvh retrieves its history from an HTTPS location derived from a name. Each either depends on the Web PKI, treats DNSSEC as an optional recommendation, or does not bind the verification-method key to the name at all. This document defines a single, normative DANE-EE key-binding profile that any DNS-anchored DID method can point at rather than reinventing: a verification method's public key is published as a TLSA record with certificate usage DANE-EE(3), selector SubjectPublicKeyInfo(1), and matching type SHA-256(1) under a DNSSEC-signed name, so that a relying party can confirm the key from the DNS root of trust with no certificate authority and no fetch from the subject. The profile binds a name to a key and the key to the specific DID document it signs, and no further; it states precisely what it does not cover, including continuity of holding, and points to where those answers live. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ranjbar-dane-did/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ranjbar-dane-did-00 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]