RFC 2065:Domain Name System Security Extensions
RFC-Ref

Time to Live


Click on the red underlined text to get to the source

... Special considerations related to "time to live", CNAMEs, and delegation ...
... signature was created, the time it expires (when it is no longer to be believed), its original time to live (which may be longer than its current time to live but cannot be shorter), the cryptographic algorithm ...
... created, the time it expires (when it is no longer to be believed), its original time to live (which may be longer than its current time to live but cannot be shorter), the cryptographic algorithm in use, and the actual ...
... time-to-live out of the digital signature, but that would allow unscrupulous servers to set arbitrarily long time to live values undetected. Instead, we include the "original" time-to-live in the signature ...
... data in addition to the current time-to-live. Unscrupulous servers under this scheme can manipulate the time to live but a security aware resolver will bound the TTL value ...



Google
Web
RFC-Ref