DNSSEC Cryptographic Algorithm Recommendation Update Process
RFC 9904, “DNSSEC Cryptographic Algorithm Recommendation Update Process”, is a Proposed Standard document published in November 2025 by W. Hardaker, W. Kumari. It updates RFC 9157. It obsoletes RFC 8624. The canonical text is published by the RFC Editor.
Abstract
The DNSSEC protocol makes use of various cryptographic algorithms to provide authentication of DNS data and proof of nonexistence. To ensure interoperability between DNS resolvers and DNS authoritative servers, it is necessary to specify both a set of algorithm implementation requirements and usage guidelines to ensure that there is at least one algorithm that all implementations support. This document replaces and obsoletes RFC 8624 and moves the canonical source of algorithm implementation requirements and usage guidance for DNSSEC from RFC 8624 to the IANA DNSSEC algorithm registries. This is done to allow the list of requirements to be more easily updated and referenced. Extensions to these registries can be made in future RFCs. This document also updates RFC 9157 and incorporates the revised IANA DNSSEC considerations from that RFC.
This document does not change the recommendation status (MUST, MAY, RECOMMENDED, etc.) of the algorithms listed in RFC 8624; that is the work of future documents.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9904 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9903 A YANG Data Model for OSPF Segment Routing over the MPLS Data Plane
- RFC 9905 Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms
- RFC 9902 A YANG Data Model for IS-IS Segment Routing over the MPLS Data Plane
- RFC 9906 Deprecate Usage of ECC-GOST within DNSSEC
- RFC 9901 Selective Disclosure for JSON Web Tokens
- RFC 9900 Updates to NETCONF Transport Port Numbers
- RFC 9899 Extensions to the YANG Data Model for Access Control Lists
- RFC 9909 Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Stateless Hash-Based Digital Signature Algorithm