<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.fanf-dnsop-sha-ll-not" target="https://datatracker.ietf.org/doc/html/draft-fanf-dnsop-sha-ll-not-00">
   <front>
      <title>Hardening DNSSEC against collision weaknesses in SHA-1 and other cryptographic hash algorithms</title>
      <author initials="T." surname="Finch" fullname="Tony Finch">
         <organization>University of Cambridge</organization>
      </author>
      <date month="March" day="9" year="2020" />
      <abstract>
	 <t>   DNSSEC deployments have often used the SHA-1 cryptographic hash
   algorithm to provide authentication of DNS data.  This document
   explains why SHA-1 is no longer secure for this purpose, and
   deprecates its use in DNSSEC signatures.  This document updates RFC
   8624.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-fanf-dnsop-sha-ll-not-00" />
   
</reference>
