Revised IANA Considerations for DNSSEC
RFC 9157, “Revised IANA Considerations for DNSSEC”, is a Proposed Standard document published in December 2021 by P. Hoffman. It updates RFC 5155, RFC 6014, RFC 8624. It has since been updated by RFC 9904. The canonical text is published by the RFC Editor.
Abstract
This document changes the review requirements needed to get DNSSEC algorithms and resource records added to IANA registries. It updates RFC 6014 to include hash algorithms for Delegation Signer (DS) records and NextSECure version 3 (NSEC3) parameters (for Hashed Authenticated Denial of Existence). It also updates RFCs 5155 and 6014, which have requirements for DNSSEC algorithms, and updates RFC 8624 to clarify the implementation recommendation related to the algorithms described in RFCs that are not on the standards track. The rationale for these changes is to bring the requirements for DS records and hash algorithms used in NSEC3 in line with the requirements for all other DNSSEC algorithms.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9157 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9156 DNS Query Name Minimisation to Improve Privacy
- RFC 9158 Update to the Object Identifier Registry for the PKIX Working Group
- RFC 9155 Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2
- RFC 9159 IPv6 Mesh over BLUETOOTH Low Energy Using the Internet Protocol Support Profile
- RFC 9154 Extensible Provisioning Protocol Secure Authorization Information for Transfer
- RFC 9160 Export of MPLS Segment Routing Label Type Information in IP Flow Information Export
- RFC 9162 Certificate Transparency Version 2.0
- RFC 9164 Concise Binary Object Representation Tags for IPv4 and IPv6 Addresses and Prefixes