Skip to main content

Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms
RFC 9905

Revision differences

Document history

Date By Action
2026-05-20
(System) Changed metadata: changed keywords to '['DNS', 'DNSSEC', 'rollover', 'agility', 'algorithm', 'SHA1']' from '[]'
2026-05-20
(System) Metadata update from RFC Editor
2026-05-20
(System) Changed author "W. Kumari": changed name from "Warren Kumari" to "W. Kumari"
2026-05-20
(System) Changed author "W. Hardaker": changed name from "Wes Hardaker" to "W. Hardaker"
2026-05-20
(System) Metadata update from RFC Editor
2025-11-30
(System)
Received changes through RFC Editor sync (created document RFC 9905, created became rfc relationship between draft-ietf-dnsop-must-not-sha1 and RFC 9905, set title to 'Deprecating …
Received changes through RFC Editor sync (created document RFC 9905, created became rfc relationship between draft-ietf-dnsop-must-not-sha1 and RFC 9905, set title to 'Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms', set abstract to 'This document deprecates the use of the RSASHA1 and
RSASHA1-NSEC3-SHA1 algorithms for the creation of DNS Public Key
(DNSKEY) and Resource Record Signature (RRSIG) records.

It updates RFCs 4034 and 5155 as it deprecates the use of these
algorithms.', set pages to 5, set standardization level to Proposed Standard, added RFC published event at 2025-11-30, created updates relation between RFC 9905 and RFC 4034, created updates relation between RFC 9905 and RFC 5155)
2025-11-30
(System) RFC published