Technical Summary
The DNSSEC protocol makes use of various cryptographic algorithms to
provide authentication of DNS data and proof of non-existence. To
ensure interoperability between DNS resolvers and DNS authoritative
servers, it is necessary to specify both a set of algorithm
implementation requirements and usage guidelines to ensure that there
is at least one algorithm that all implementations support. This
document updates RFC8624 by moving the canonical source of algorithm
implementation requirements and usage guidance for DNSSEC from
RFC8624 to an IANA registry. This is done both to allow the list to
be more easily updated, and to allow the list to be more easily
referenced. Future extensions to this registry can be made under
new, incremental update RFCs.
The document does not change the status (MUST, MAY, RECOMMENDED, etc)
of any of the algorithms listed in RFC8624; that is the work of
future documents.
Working Group Summary
From the shepherd's write-up: "WG consensus was solid. There was
discussions around Section 2 "Adding usage
and implementation recommendations to the IANA DNSSEC tables",
but nothing in conflict."
Document Quality
Also from the shepherd's write-up: "As this document is
updating IANA tables, it is more about documenting existing usage
and not about implementations."
The IETF Last Call received several reviews and the I-D was updated
(verified by the AD).
Personnel
The Document Shepherd for this document is Tim Wicinski. The Responsible
Area Director is Éric Vyncke.
IANA Note
This document adds usage and implementation recommandations to the
existing IANA DNSSEC registries.