Skip to content

change(dnssec): cite RFC 10026 (BCP 246) for DS automation - #149

Draft
jdevalk wants to merge 1 commit into
mainfrom
change/dnssec-ds-automation-2026-08-02
Draft

change(dnssec): cite RFC 10026 (BCP 246) for DS automation#149
jdevalk wants to merge 1 commit into
mainfrom
change/dnssec-ds-automation-2026-08-02

Conversation

@jdevalk

@jdevalk jdevalk commented Aug 2, 2026

Copy link
Copy Markdown
Owner

What changed

src/content/spec/security/dnssec.md:

  • Step 3 of How to implement now prefers the automated CDS/CDNSKEY path and names the acceptance checks the BCP puts on the registrar/registry side: records must agree across every authoritative nameserver, the resulting DS must be confirmed not to break validation before it is published, and the DS TTL should drop to a few minutes around a change so a bad one rolls back fast.
  • Operational hygiene gains the BCP's least obvious instruction — keep a non-automated route to the DS open even when automation works, because a provider that stops cooperating mid-migration is exactly when you need to change the DS and cannot ask it to.
  • updated bumped; changelog entry added (changed).

Why now

RFC 10026 — Operational Recommendations for DNSSEC Delegation Signer (DS) Automation was published as BCP 246 in July 2026 (https://www.rfc-editor.org/rfc/rfc10026.html). It is the first best-current-practice-level document for the mechanism the page already recommended in passing, and it makes CDS/CDNSKEY support a MUST for the entities operating that automation (alongside RFC 9615 bootstrapping).

The page's existing honest caveat — DNSSEC "is only worth taking on with tooling that handles rollovers automatically" — now has a standard behind it rather than being our assertion.

Sources

  • Primary: RFC 10026 (BCP 246), IETF, July 2026.
  • Retained: RFC 4033, RFC 4035, ICANN DNSSEC overview.
  • Removed: the Internet Society "Deploying DNSSEC" (deploy360) landing page, to keep sources at four per CLAUDE.md and because a BCP outranks an advocacy-programme landing page. Note: I could not fetch that URL during this run to confirm whether it still resolves — the swap is argued on primary-sources-first grounds, not on a liveness claim.

Status

Unchanged at optional. RFC 10026 is operational guidance for registrars and registries, not a new obligation on site owners; the honest caveat about DNSSEC misconfiguration taking a domain offline still applies. Nothing here moves the bar toward recommended.

Note for the maintainer

The changelog entry is borderline per CLAUDE.md — this is a citation upgrade plus a tightened step, not a full rewrite. I included it because a new BCP for DNSSEC DS handling seems worth surfacing to readers, but drop the entry if you disagree.

🤖 Generated with Claude Code

RFC 10026 was published as BCP 246 in July 2026 — the operational
best current practice for CDS/CDNSKEY-driven DS maintenance. The page
previously mentioned CDS/CDNSKEY as an aside; it now names the BCP,
prefers the automated path, and carries the BCP's least obvious
instruction: keep a manual route to the DS open, because a provider
that stops cooperating mid-migration is exactly when you need it.

Swapped the Internet Society deploy360 landing page out of sources for
the BCP, per primary-sources-first.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying specification-website with  Cloudflare Pages  Cloudflare Pages

Latest commit: d5c13f5
Status: ✅  Deploy successful!
Preview URL: https://f17114fd.specification-website.pages.dev
Branch Preview URL: https://change-dnssec-ds-automation.specification-website.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant