Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms
RFC 9905, “Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms”, is a Proposed Standard document published in November 2025 by W. Hardaker, W. Kumari. It updates RFC 4034, RFC 5155. The canonical text is published by the RFC Editor.
Abstract
This document deprecates the use of the RSASHA1 and RSASHA1-NSEC3-SHA1 algorithms for the creation of DNS Public Key (DNSKEY) and Resource Record Signature (RRSIG) records.
It updates RFCs 4034 and 5155 as it deprecates the use of these algorithms.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9905 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9904 DNSSEC Cryptographic Algorithm Recommendation Update Process
- RFC 9906 Deprecate Usage of ECC-GOST within DNSSEC
- RFC 9903 A YANG Data Model for OSPF Segment Routing over the MPLS Data Plane
- RFC 9902 A YANG Data Model for IS-IS Segment Routing over the MPLS Data Plane
- RFC 9901 Selective Disclosure for JSON Web Tokens
- RFC 9909 Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Stateless Hash-Based Digital Signature Algorithm
- RFC 9900 Updates to NETCONF Transport Port Numbers
- RFC 9899 Extensions to the YANG Data Model for Access Control Lists