| rfc9904v3.txt | rfc9904.txt | |||
|---|---|---|---|---|
| skipping to change at line 96 ¶ | skipping to change at line 96 ¶ | |||
| authentication of DNS data. The DNSSEC signing algorithms are | authentication of DNS data. The DNSSEC signing algorithms are | |||
| defined by various RFCs, including [RFC4034], [RFC4509], [RFC5155], | defined by various RFCs, including [RFC4034], [RFC4509], [RFC5155], | |||
| [RFC5702], [RFC5933], [RFC6605], and [RFC8080]. | [RFC5702], [RFC5933], [RFC6605], and [RFC8080]. | |||
| To ensure interoperability, a set of "mandatory-to-implement" DNS | To ensure interoperability, a set of "mandatory-to-implement" DNS | |||
| Public Key (DNSKEY) algorithms are defined in [RFC8624]. To make the | Public Key (DNSKEY) algorithms are defined in [RFC8624]. To make the | |||
| current status of the algorithms more easily accessible and | current status of the algorithms more easily accessible and | |||
| understandable, and to make future changes to these recommendations | understandable, and to make future changes to these recommendations | |||
| easier to publish, this document moves the canonical status of the | easier to publish, this document moves the canonical status of the | |||
| algorithms from [RFC8624] to the IANA DNSSEC algorithm registries. | algorithms from [RFC8624] to the IANA DNSSEC algorithm registries. | |||
| Additionally, as advice to operators, it adds recommendations for | This document also incorporates the revised IANA DNSSEC | |||
| deploying and using these algorithms. | considerations from [RFC9157]. Additionally, as advice to operators, | |||
| it adds recommendations for deploying and using these algorithms. | ||||
| This is similar to the process used for the "TLS Cipher Suites" | This is similar to the process used for the "TLS Cipher Suites" | |||
| registry [TLS-ciphersuites], where the canonical list of cipher | registry [TLS-ciphersuites], where the canonical list of cipher | |||
| suites is in the IANA registry, and RFCs reference the IANA registry. | suites is in the IANA registry, and RFCs reference the IANA registry. | |||
| 1.1. Document Audience | 1.1. Document Audience | |||
| The columns added to the IANA "DNS Security Algorithm Numbers" | The columns added to the IANA "DNS Security Algorithm Numbers" | |||
| [DNSKEY-IANA] and "Digest Algorithms" [DS-IANA] registries target | [DNSKEY-IANA] and "Digest Algorithms" [DS-IANA] registries target | |||
| DNSSEC operators and implementers. | DNSSEC operators and implementers. | |||
| End of changes. 1 change blocks. | ||||
| 2 lines changed or deleted | 3 lines changed or added | |||
This html diff was produced by rfcdiff 1.48. | ||||