ietf-corpus

rfc-9905

Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms

W. Hardaker, W. Kumari
date2025-11 streamIETF areaops wgdnsop statusPROPOSED STANDARD pages5 canonicalhttps://www.rfc-editor.org/rfc/rfc9905 doi10.17487/RFC9905
This document deprecates the use of the RSASHA1 and RSASHA1-NSEC3-SHA1 algorithms for the creation of DNS Public Key (DNSKEY) and Resource Record Signature (RRSIG) records. It updates RFCs 4034 and 5155 as it deprecates the use of these algorithms.

updates