[Dnssec-deployment] Is RSASHA256 mature enough for a TLD?

Edward Lewis Ed.Lewis at neustar.biz
Fri Jun 11 15:51:58 EDT 2010


I'm looking for the conventional wisdom on whether we should use 
RSASHA1 or RSASHA256 for our next zone to sign.  Trying to avoid 
starting a key mgt instance on RSASHA1 and then having to roll to 
RSASHA256 in the near future.

I see the DURZ uses RSASHA256...but no one can validate it for some 
reason. (;))


-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis
NeuStar                    You can leave a voice message at +1-571-434-5468

Discussing IPv4 address policy is like deciding what to eat on the Titanic.


More information about the Dnssec-deployment mailing list