[dnssec-deployment] what to hand your parent

Jakob Schlyter jakob at rfc.se
Wed Sep 20 08:36:48 EDT 2006


On 20 sep 2006, at 14.30, Steve Crocker wrote:

> Where do we stand on transition to hash algorithms stronger than  
> SHA1?  I am hearing pressure to move beyond SHA1.

if your referring to the hash of the DS, .se publishes DS records  
with both SHA-1 and SHA-256.
for DNSKEYs with RSA/SHA256, perhaps Jelte can fill us in on draft- 
ietf-dnsext-dnssec-rsasha256-01.txt.

	jakob




More information about the Dnssec-deployment mailing list