Internet Engineering Task Force (IETF) S. Rose
Request for Comments: 6725 NIST
Category: Standards Track August 2012
ISSN: 2070-1721
DNS Security (DNSSEC) DNSKEY Algorithm IANA Registry Updates
Rose Standards Track [Page 1]
RFC 6725 IANA Registry Update August 2012
Table of Contents
1. Introduction
The Domain Name System (DNS) Security Extensions (DNSSEC, defined by [RFC4033], [RFC4034], [RFC4035], [RFC4509], [RFC5155], and [RFC5702]) use digital signatures over DNS data to provide source authentication and integrity protection. DNSSEC uses an IANA registry to list codes for digital signature algorithms (consisting of an asymmetric cryptographic algorithm and a one-way hash function).
2. The DNS Security Algorithm Numbers Sub-Registry
The DNS Security Algorithm Numbers sub-registry (part of the Domain Name System Security (DNSSEC) Algorithm Numbers registry) contains a set of entries that contain errors. There are additional differences to entries that are described in Section 2.1, and the complete list of changed registry entries is in Section 2.2.
2.1. Updates and Additions
This document updates three entries in the Domain Name System Security (DNSSEC) Algorithm Numbers registry:
Rose Standards Track [Page 2]
RFC 6725 IANA Registry Update August 2012
The above entries are changed to "Reserved" because they were placeholders for algorithms that were not fully specified for use with DNSSEC. Older implementations may still have these algorithm codes assigned, so these codes are reserved to prevent potential incompatibilities.
2.2. DNS Security Algorithm Numbers Sub-Registry Table
The list of DNS Security Algorithm Numbers sub-registry entry changes is given below. All other existing entries in the sub-registry table are unchanged by this document and are not shown. The other two sub-registries in the Domain Name System Security (DNSSEC) Algorithm Numbers registry (DNS KEY Record Diffie-Hellman Prime Lengths and DNS KEY Record Diffie-Hellman Well-Known Prime/Generator Pairs) are not changed in any way by this document.
Number Description Mnemonic Signing Sec. Reference
------ ----------- -------- ------- --------- ---------
0 Reserved [RFC4034],
[RFC4398]
1 RSA/MD5 RSAMD5 N Y [RFC3110],
(deprecated; [RFC4034]
see 5)
253 private PRIVATEDNS Y Y [RFC4034]
algorithm
254 private PRIVATEOID Y Y [RFC4034]
algorithm OID
Rose Standards Track [Page 3]
RFC 6725 IANA Registry Update August 2012 3. IANA ConsiderationsThis document updates a set of DNS Security Algorithm Numbers sub-registry entries as given in Section 2.2. The changes include moving three registry entries to "Reserved" and updating the reference list for entries.
4. Security Considerations
This document updates the Domain Name System Security (DNSSEC) Algorithm Numbers registry. It is not meant to be a discussion on algorithm superiority. No new security considerations are raised in this document.
5. Informative References
[RFC3110] Eastlake, D., "RSA/SHA-1 SIGs and RSA KEYs in the Domain
Rose Standards Track [Page 4]
RFC 6725 IANA Registry Update August 2012
Author's Address