Algorithm Implementation Requirements and Usage Guidance for DNSSEC
RFC 8624, “Algorithm Implementation Requirements and Usage Guidance for DNSSEC”, is a Proposed Standard document published in June 2019 by P. Wouters, O. Sury. It obsoletes RFC 6944. It has since been updated by RFC 9157. It has been obsoleted by RFC 9904 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
The DNSSEC protocol makes use of various cryptographic algorithms in order to provide authentication of DNS data and proof of nonexistence. To ensure interoperability between DNS resolvers and DNS authoritative servers, it is necessary to specify a set of algorithm implementation requirements and usage guidelines to ensure that there is at least one algorithm that all implementations support. This document defines the current algorithm implementation requirements and usage guidance for DNSSEC. This document obsoletes RFC 6944.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8624 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8623 Stateful Path Computation Element Protocol Extensions for Usage with Point-to-Multipoint TE Label Switched Paths
- RFC 8625 Ethernet Traffic Parameters with Availability Information
- RFC 8622 A Lower-Effort Per-Hop Behavior for Differentiated Services
- RFC 8621 The JSON Meta Application Protocol for Mail
- RFC 8627 RTP Payload Format for Flexible Forward Error Correction
- RFC 8620 The JSON Meta Application Protocol
- RFC 8628 OAuth 2.0 Device Authorization Grant
- RFC 8619 Algorithm Identifiers for the HMAC-based Extract-and-Expand Key Derivation Function