Skip to main content

Last Call Review of draft-ietf-dnsop-must-not-sha1-03
review-ietf-dnsop-must-not-sha1-03-artart-lc-leiba-2025-02-21-00

Request Review of draft-ietf-dnsop-must-not-sha1
Requested revision No specific revision (document currently at 10)
Type IETF Last Call Review
Team ART Area Review Team (artart)
Deadline 2025-03-06
Requested 2025-02-20
Authors Wes Hardaker , Warren Kumari
I-D last updated 2025-11-30 (Latest revision 2025-09-10)
Completed reviews Dnsdir IETF Last Call review of -03 by Florian Obser (diff)
Artart IETF Last Call review of -03 by Barry Leiba (diff)
Secdir IETF Last Call review of -03 by Yoav Nir (diff)
Genart IETF Last Call review of -03 by Behcet Sarikaya (diff)
Dnsdir Telechat review of -05 by Florian Obser (diff)
Opsdir Telechat review of -06 by Thomas Graf (diff)
Secdir Telechat review of -06 by Yoav Nir (diff)
Dnsdir Telechat review of -06 by Peter van Dijk (diff)
Assignment Reviewer Barry Leiba
State Completed
Request IETF Last Call review on draft-ietf-dnsop-must-not-sha1 by ART Area Review Team Assigned
Posted at https://mailarchive.ietf.org/arch/msg/art/2ADuA4TrTDi9P9FNfV9Xq_lQ5e4
Reviewed revision 03 (document currently at 10)
Result Ready w/nits
Completed 2025-02-21
review-ietf-dnsop-must-not-sha1-03-artart-lc-leiba-2025-02-21-00
By themselves (without “RSA”), SHA-1, SHA-256 and other “SHA-nnn” designations
are hash (or digest) algorithms, not encryption algorithms, and we should
probably be more careful about what we call them. In this document it doesn’t
matter much, because this is just about depreciation and not documentation of
their use, but, still we have the opportunity to get it right.

So:
- “DNSSEC [RFC9364] originally made extensive use of SHA-1 as a cryptographic
verification algorithm” should say “cryptographic hash algorithm” - “Since
then, multiple other signing algorithms with stronger cryptographic strength”
can just say “other algorithms” - For “by guiding signers to choose a more
interoperable signing algorithm.” maybe just drop the word “signing” (and I
might say “secure and interoperable”)

Also, “algorithms with stronger cryptographic strengths” sounds odd.  Maybe
“algorithms with more cryptographic strength”?  Or maybe “stronger
cryptographic algorithms”?