TLDDNSSEC

What DNSSEC material the registry accepts for a domain under this TLD. model names the RFC 5910 data interface: ds_data takes DS records (ds_records on a DNSSEC change), key_data takes DNSKEY records (key_records), none takes neither. digest_types and algorithms are the IANA numbers the registry accepts on a record it is sent; digest_types is empty under key_data, where the registry computes the digest itself. ds_dnskey reports whether a DS record may carry the DNSKEY it was derived from. max_records is the most records the registry accepts on one domain, or 0 where it has stated no limit.

  • Resource type identifier

  • RFC 5910 data interface the registry runs.

    values
    • none = SecDNSModelNone
    • ds_data = SecDNSModelDSData
    • key_data = SecDNSModelKeyData
  • IANA DS digest types accepted on a DS record, ascending. Empty unless model is ds_data.

  • IANA DNSSEC algorithm numbers accepted on a DS or DNSKEY record, ascending. Empty when model is none.

  • Whether a DS record may carry the DNSKEY it was derived from. Only ever true under ds_data.

  • Most DS or DNSKEY records the registry accepts on one domain. 0 means it has stated no limit.