RFC 2065:Domain Name System Security Extensions
RFC-Ref

NS


Click on the red underlined text to get to the source

... resource record for each resource type under that name except for glue RRs and delgation point NS RRs. A security aware server ...
... avoid conflicts, only the KEY RR in the superzone should be signed and the NS and any A (glue) RRs should only be signed in the subzone. The SOA and any other RRs ...


... On the retrieval of NS RRs, the zone key KEY RR ...


... RRs and delegation point NS RRs. You can then make one pass inserting all the zone SIGs. As you proceed you hash ...
... 3. SIGs to authenticate non-authoritative data (glue records and NS RRs for subzones) are unnecessary and MUST NOT be sent. (Note ...
... section it MUST appear in the additional information section. This is a change in the existing standard which contemplates only NS and SOA RRs in the authority section. ...


... security aware. The same is true for a non-existent type under an existing name. This is a change in the existing standard which contemplates only NS and SOA RRs in the authority ...


... RR with non-null key information appearing with the NS RRs for the sub-zone. These make it possible to descend within the tree ...



Google
Web
RFC-Ref