RFC 9905 · PROPOSED STANDARD · 2025

Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms

Overview

RFC 9905, “Deprecating the Use of SHA-1 in DNSSEC Signature Algorithms”, is a Proposed Standard document published in November 2025 by W. Hardaker, W. Kumari. It updates RFC 4034, RFC 5155. The canonical text is published by the RFC Editor.

Abstract

This document deprecates the use of the RSASHA1 and RSASHA1-NSEC3-SHA1 algorithms for the creation of DNS Public Key (DNSKEY) and Resource Record Signature (RRSIG) records.

It updates RFCs 4034 and 5155 as it deprecates the use of these algorithms.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9905 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 4034 RFC 5155
Other RFCs from 2025

Who Is Online

In total there are 94 users online: 0 registered, 86 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372