RFC 9905: Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms
Recent RFCs 2025-11-30
Summary:
This document deprecates the use of the RSASHA1 and
RSASHA1-NSEC3-SHA1 algorithms for the creation of DNS Public Key
(DNSKEY) and Resource Record Signature (RRSIG) records.
It updates RFCs 4034 and 5155 as it deprecates the use of these
algorithms.