Internet Engineering Task Force (IETF) S. Kitterman Request for Comments: 8301 Kitterman Technical Services Updates: 6376 January 2018 Category: Standards Track ISSN: 2070-1721Cryptographic Algorithm and Key Usage Update to DomainKeys Identified Mail (DKIM)
Kitterman Standards Track [Page 1]
RFC 8301 DKIM Crypto Usage Update January 2018
Table of Contents
1. Introduction
DKIM [RFC6376] signs email messages by creating hashes of the message headers and content and signing the header hash with a digital signature. Message recipients fetch the signature verification key from the DNS where it is stored in a TXT record.
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.
Kitterman Standards Track [Page 2]
RFC 8301 DKIM Crypto Usage Update January 2018 3. Updates to DKIM Signing and Verification RequirementsThis document updates [RFC6376] as follows:
3.1. Signing and Verification Algorithms
DKIM supports multiple digital signature algorithms. Two algorithms are defined by this specification at this time: rsa-sha1 and rsa-sha256. Signers MUST sign using rsa-sha256. Verifiers MUST be able to verify using rsa-sha256. rsa-sha1 MUST NOT be used for signing or verifying.
3.2. Key Sizes
Selecting appropriate key sizes is a trade-off between cost, performance, and risk. Since short RSA keys more easily succumb to off-line attacks, Signers MUST use RSA keys of at least 1024 bits for all keys. Signers SHOULD use RSA keys of at least 2048 bits. Verifiers MUST be able to validate signatures with keys ranging from 1024 bits to 4096 bits, and they MAY be able to validate signatures with larger keys. Verifier policies can use the length of the signing key as one metric for determining whether a signature is acceptable. Verifiers MUST NOT consider signatures using RSA keys of less than 1024 bits as valid signatures.
4. Security Considerations
This document does not change the Security Considerations of [RFC6376]. It reduces the risk of signature compromise due to weak cryptography. The SHA-1 risks discussed in Section 3 of [RFC6194] are resolved due to rsa-sha1 no longer being used by DKIM.
Kitterman Standards Track [Page 3]
RFC 8301 DKIM Crypto Usage Update January 2018 5. IANA ConsiderationsIANA has updated the Reference and Status fields of the "sha1" registration in the "DKIM Hash Algorithms" registry. The registration now appears as follows:
+------+---------------------+----------+
| Type | Reference | Status |
+------+---------------------+----------+
| sha1 | [RFC6376] [RFC8301] | historic |
+------+---------------------+----------+
6. References
6.1. Normative References
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
6.2. Informative References
[RFC6194] Polk, T., Chen, L., Turner, S., and P. Hoffman, "Security
Kitterman Standards Track [Page 4]
RFC 8301 DKIM Crypto Usage Update January 2018
Acknowledgements