RFC 6975 · PROPOSED STANDARD · 2013

Signaling Cryptographic Algorithm Understanding in DNS Security Extensions

Overview

RFC 6975, “Signaling Cryptographic Algorithm Understanding in DNS Security Extensions”, is a Proposed Standard document published in July 2013 by S. Crocker, S. Rose. The canonical text is published by the RFC Editor.

Abstract

The DNS Security Extensions (DNSSEC) were developed to provide origin authentication and integrity protection for DNS data by using digital signatures. These digital signatures can be generated using different algorithms. This document specifies a way for validating end-system resolvers to signal to a server which digital signature and hash algorithms they support. The extensions allow the signaling of new algorithm uptake in client code to allow zone administrators to know when it is possible to complete an algorithm rollover in a DNSSEC-signed zone.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 6975 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2013

Who Is Online

In total there are 447 users online: 0 registered, 440 guests and 7 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Baiduspider Facebook Googlebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354